Showing 2 vulnerabilities on this page for python-socketio

Signals CISA KEV Ransomware Nuclei
miguelgrinberg vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

python-socketio: Binary attachment accumulation can cause denial of service

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay

CWE-770Aug 11, 2026
CVSS7.5v3.1EPSS0.279%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments

python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-

CWE-502Oct 6, 2025
CVSS6.4v3.1EPSS0.446%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX