Description
Engine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Recommendation
Update the engine.io package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.6.0
- Patched version(s): 3.6.0
References
Related Issues
- Socket.IO: Engine.IO Polling Transport Connection Exhaustion - CVE-2026-59725
- Resource exhaustion in socket.io-parser - CVE-2020-36049
- Uncontrolled Resource Consumption in strapi - CVE-2020-8123
- jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext - jose-node-cjs-runtime - CVE-2024-28176
You might also like:
- Tags:
- npm
- engine.io
Anything's wrong? Let us know Last updated on May 29, 2025


