Description
Engine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Recommendation
Update the engine.io package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.6.0
- Patched version(s): 3.6.0
References
Could your website be exposed too?
SmartScanner can check your website for Resource exhaustion in engine.io and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Socket.IO: Engine.IO Polling Transport Connection Exhaustion - CVE-2026-59725
- Resource exhaustion in socket.io-parser - CVE-2020-36049
- Uncontrolled Resource Consumption in strapi - CVE-2020-8123
- jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-cjs-runtime - CVE-2024-28176
You might also like:
See something that needs correcting? Let us knowUpdated May 29, 2025


