Loading vulnerability details...
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
| Version range | Used by | Fixed version |
|---|---|---|
>=4.0.0 <4.2.6 | socket.io@4.x and socket.io-client@4.x | 4.2.6 |
>=3.4.0 <3.4.4 | socket.io@2.x | 3.4.4 |
<3.3.5 | socket.io-client@2.x | 3.3.5 |
There is no known workaround except upgrading to a safe version.
If you have any questions or comments about this advisory:
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
| Version range | Used by | Fixed version |
|---|---|---|
>=4.0.0 <4.2.6 | socket.io@4.x and socket.io-client@4.x | 4.2.6 |
>=3.4.0 <3.4.4 | socket.io@2.x | 3.4.4 |
<3.3.5 | socket.io-client@2.x | 3.3.5 |
There is no known workaround except upgrading to a safe version.
If you have any questions or comments about this advisory:
This medium-severity vulnerability could be exploited under certain conditions to compromise security controls or access sensitive information. Should be addressed in a timely manner.
Probability of exploitation in the next 30 days · more likely than 48.7% of all CVEs.
Apply security patches to version 3.3.5, 3.4.4, 4.2.6 immediately
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior