| Name | CVE-2026-69185 |
| Description | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| node-socket.io-parser (PTS) | bullseye | 4.0.2-1 | vulnerable |
| bookworm | 4.2.1+~3.1.0-2 | vulnerable | |
| trixie | 4.2.1+~3.1.0-3 | vulnerable | |
| forky, sid | 4.2.1+~3.1.0-4 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| node-socket.io-parser | source | (unstable) | (unfixed) |
https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
Fixed by: https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4 (socket.io-parser@4.2.7)
Fixed by: https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291 (socket.io-parser@3.4.5)
Fixed by: https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240 (socket.io-parser@3.3.6)