CVE-2026-69185

HIGH

Socket.IO: Zero-attachment Memory Exhaustion

Title source: cna
STIX 2.1

Description

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 27.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-754
Status published
Products (6)
npm/socket.io-parser 0 - 3.3.6npm
npm/socket.io-parser 3.4.0 - 3.4.5npm
npm/socket.io-parser 4.0.0 - 4.2.7npm
socketio/socket.io < 3.3.6
socketio/socket.io >= 3.4.0, < 3.4.5
socketio/socket.io >= 4.0.0, < 4.2.7
Published Aug 03, 2026
Tracked Since Aug 04, 2026