Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-69185

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

A flaw was found in Socket.IO. A remote attacker could send a specially crafted packet that causes the server to buffer a large number of binary attachments. This can lead to the server running out of memory, resulting in a denial of service (DoS).

Отчет

This is an Important denial of service vulnerability in Socket.IO, affecting Red Hat products that utilize the socket.io-parser component. An unauthenticated remote attacker can exploit this flaw by sending specially crafted packets, leading to excessive memory consumption and causing the service to become unavailable.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Affected
Red Hat Hardened Imagesdotnet8.0Not affected
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2510755socket.io-parser: Socket.IO: Denial of Service via memory exhaustion from crafted packets

EPSS

Процентиль: 41%
0.00503
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
nvd
28 дней назад

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

CVSS3: 7.5
debian
28 дней назад

Socket.IO enables bidirectional and low-latency communication for ever ...

CVSS3: 7.5
github
28 дней назад

Socket.IO: Zero-attachment Memory Exhaustion

EPSS

Процентиль: 41%
0.00503
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-69185