Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-69185

Опубликовано: 03 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

EPSS

Процентиль: 28%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
redhat
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
debian
28 дней назад

Socket.IO enables bidirectional and low-latency communication for ever ...

CVSS3: 7.5
github
28 дней назад

Socket.IO: Zero-attachment Memory Exhaustion

EPSS

Процентиль: 28%
0.00346
Низкий

7.5 High

CVSS3

Дефекты

CWE-20