Security Advisory

CVE-2026-69185

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-03 19:09:10
Last updated 2026-08-03 20:31:54
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.