Vulnerabilities/

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

Severity:
High

Description

An unauthenticated remote attacker can cause a denial of service in affected versions of engine.io by opening Engine.IO polling sessions and sending an invalid binary POST request with:

against an Engine.IO protocol v4 polling transport.

Recommendation

Update the engine.io package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
engine.io
Anything's wrong? Let us know Last updated on July 20, 2026