HIGH 7.5 npm

Socket.IO: Zero-attachment Memory Exhaustion

GHSA-2m8v-j782-fhvr · CVE-2026-69185

Published · Modified

Description

Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Patches

Version range Used by Fixed version
>=4.0.0 <4.2.7 socket.io@4.x and socket.io-client@4.x 4.2.7
>=3.4.0 <3.4.5 socket.io@2.x 3.4.5
<3.3.6 socket.io-client@2.x 3.3.6

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

  • Open a discussion here

Ready to move

Start Securing

Free, no credit card | First findings in minutes