CVE-2026-69185

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 20:17

Updated : 2026-09-10 20:30


NVD link : CVE-2026-69185

Mitre link : CVE-2026-69185

CVE.ORG link : CVE-2026-69185


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-754

Improper Check for Unusual or Exceptional Conditions