Socket

Engine.Io

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 08.07.2026 15:37:52
  • Zuletzt bearbeitet 13.07.2026 15:07:44

Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: applicati...

  • EPSS 0.34%
  • Veröffentlicht 08.07.2026 15:35:39
  • Zuletzt bearbeitet 13.07.2026 15:08:37

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients obj...

  • EPSS 1.33%
  • Veröffentlicht 08.05.2023 21:15:11
  • Zuletzt bearbeitet 13.02.2025 17:16:26

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` paren...

Exploit
  • EPSS 1.94%
  • Veröffentlicht 22.11.2022 01:15:37
  • Zuletzt bearbeitet 21.11.2024 07:24:06

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js proce...

  • EPSS 2.76%
  • Veröffentlicht 12.01.2022 19:15:09
  • Zuletzt bearbeitet 21.11.2024 06:45:12

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js proce...

Exploit
  • EPSS 3.24%
  • Veröffentlicht 08.01.2021 00:15:11
  • Zuletzt bearbeitet 21.11.2024 05:28:41

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.