Description
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
Recommendation
Update the socket.io-parser package to the latest compatible version. Followings are version details:
Affected version(s): **< 3.3.6 >= 3.4.0, < 3.4.5 >= 4.0.0, < 4.2.7** Patched version(s): **3.3.6 3.4.5 4.2.7**
References
Related Issues
- Socket.IO: Engine.IO Polling Transport Connection Exhaustion - CVE-2026-59725
- Devalue is vulnerable to denial of service due to memory exhaustion in devalue.parse - CVE-2026-22774
- devalue vulnerable to denial of service due to memory/CPU exhaustion in devalue.parse - CVE-2026-22775
- socket.io allows an unbounded number of binary attachments - CVE-2026-33151
You might also like:
- Tags:
- npm
- socket.io-parser
Anything's wrong? Let us know Last updated on August 03, 2026


