Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33151

Опубликовано: 20 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

РелизСтатусПримечание
devel

not-affected

4.2.1+~3.1.0-4
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

needs-triage

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
nvd
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

CVSS3: 7.5
debian
5 месяцев назад

Socket.IO is an open source, real-time, bidirectional, event-based, co ...

github
5 месяцев назад

socket.io allows an unbounded number of binary attachments

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость кодировщика и декодировщика пакетов socket.io parser библиотеки Socket.IO, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3