Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2m8v-j782-fhvr | Socket.IO: Zero-attachment Memory Exhaustion |
Mon, 03 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. | |
| Title | Socket.IO: Zero-attachment Memory Exhaustion | |
| Weaknesses | CWE-20 CWE-754 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-03T20:31:54.428Z
Reserved: 2026-08-03T16:00:23.482Z
Link: CVE-2026-69185
Updated: 2026-08-03T20:31:46.564Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA