Description
An unauthenticated remote attacker can cause a denial of service in affected versions of engine.io by opening Engine.IO polling sessions and sending an invalid binary POST request with:
against an Engine.IO protocol v4 polling transport.
Recommendation
Update the engine.io package to the latest compatible version. Followings are version details:
- Affected version(s): >= 4.1.0, < 6.6.7
- Patched version(s): 6.6.7
References
Related Issues
- Socket.IO: Zero-attachment Memory Exhaustion - CVE-2026-69185
- Resource exhaustion in engine.io - CVE-2020-36048
- Electerm Local code through electerm's single-instance socket - CVE-2026-45353
- @conform-to/dom parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields - CVE-2026-49250
You might also like:
- Tags:
- npm
- engine.io
Anything's wrong? Let us know Last updated on July 20, 2026


