Description
An unauthenticated remote attacker can cause a denial of service in affected versions of engine.io by opening Engine.IO polling sessions and sending an invalid binary POST request with:
against an Engine.IO protocol v4 polling transport.
Recommendation
Update the engine.io package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.1.0, < 6.6.7
- Patched version(s): 6.6.7
References
Could your website be exposed too?
SmartScanner can check your website for Socket.IO: Engine.IO Polling Transport Connection Exhaustion and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Socket.IO: Zero-attachment Memory Exhaustion - CVE-2026-69185
- Resource exhaustion in engine.io - CVE-2020-36048
- Electerm Local code through electerm's single-instance socket - CVE-2026-45353
- @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields - CVE-2026-49250


