Vulnerabilities/

Resource exhaustion in engine.io

Severity:
High

Description

Engine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

Recommendation

Update the engine.io package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
engine.io
Anything's wrong? Let us know Last updated on May 29, 2025