PT-2026-26200 · Socket.Io · Socket.Io

X4Cc3

·

Published

2026-03-18

·

Updated

2026-03-21

·

CVE-2026-33151

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Socket.IO versions prior to 3.3.5 Socket.IO versions 3.3.5 through 3.4.4 Socket.IO versions 4.0.0 through 4.2.6
Description Socket.IO is a real-time, bidirectional, event-based communication framework. A specially crafted Socket.IO packet can cause the server to wait for and buffer a large number of binary attachments, potentially leading to server memory exhaustion.
Recommendations Versions prior to 3.3.5: Upgrade to version 3.3.5 or later. Versions 3.3.5 through 3.4.4: Upgrade to version 3.4.4 or later. Versions 4.0.0 through 4.2.6: Upgrade to version 4.2.6 or later.

Exploit

Fix

RCE

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2026-33151
GHSA-677M-J7P3-52F9

Affected Products

Socket.Io