Vulnerability Description
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b
- https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a
- https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb1
- https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
FAQ
What is CVE-2026-69185?
CVE-2026-69185 is a vulnerability with a CVSS score of 7.5 (HIGH). Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of ...
How severe is CVE-2026-69185?
CVE-2026-69185 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-69185?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.