Description
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
Recommendation
Update the socket.io-parser package to the latest compatible version. Followings are version details:
Affected version(s): **>= 4.0.0, < 4.2.6 >= 3.4.0, < 3.4.4 < 3.3.5** Patched version(s): **4.2.6 3.4.4 3.3.5**
References
Related Issues
- Socket.IO: Zero-attachment Memory Exhaustion - CVE-2026-69185
- Axios: unbounded recursion in toFormData causes DoS via deeply nested request data - CVE-2026-42039
- @asymmetric-effort/specifyjs: URL parse failure silently allows request - CVE-2026-50288
- Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS - CVE-2026-62324
You might also like:
- Tags:
- npm
- socket.io-parser
Anything's wrong? Let us know Last updated on March 20, 2026


