{"id":"CVE-2026-69185","summary":"Socket.IO: Zero-attachment Memory Exhaustion","details":"Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.","aliases":["GHSA-2m8v-j782-fhvr"],"modified":"2026-08-04T11:31:16.062642284Z","published":"2026-08-03T19:09:10.073Z","database_specific":{"cwe_ids":["CWE-20","CWE-754"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69185.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69185.json"},{"type":"FIX","url":"https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4"},{"type":"FIX","url":"https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240"},{"type":"FIX","url":"https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291"},{"type":"ADVISORY","url":"https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69185"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/socketio/socket.io","events":[{"introduced":"0"},{"fixed":"98e61b941fb9915614e0b962588817efb795020c"},{"fixed":"e590976beb69f98faa44da7653f4ab55c5e0e61a"},{"introduced":"5eaeffc8e2244b73dd13fd2562c9684ad289997b"},{"fixed":"4054894738817f5a2125e6e6b18e79d92c75ab33"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.3.6"},{"introduced":"3.4.0"},{"fixed":"3.4.5"},{"introduced":"4.0.0"},{"fixed":"4.2.7"}],"source":"AFFECTED_FIELD"}}],"versions":["socket.io-parser@3.3.5","socket.io-parser@3.4.4","socket.io-adapter@2.5.8","engine.io-client@6.6.6","engine.io@6.6.9","socket.io-adapter@2.5.7","engine.io-client@6.6.5","engine.io@6.6.8","engine.io@6.6.7","engine.io@6.6.6","socket.io@4.8.3","socket.io-client@4.8.3","socket.io-parser@4.2.5","socket.io-adapter@2.5.6","engine.io-client@6.6.4","socket.io@4.8.2","socket.io-client@4.8.2","engine.io@6.6.5","@socket.io/redis-streams-emitter@0.1.1","@socket.io/redis-streams-emitter@0.1.0","@socket.io/cluster-adapter@0.3.0","@socket.io/postgres-emitter@0.1.1","engine.io@6.6.4","engine.io@6.6.3","engine.io-client@6.6.3","socket.io@4.8.1","socket.io-client@4.8.1","engine.io-client@6.6.2","engine.io@6.6.2","socket.io@4.8.0","socket.io-client@4.8.0","engine.io@6.6.1","engine.io-client@6.6.1","@socket.io/cluster-engine@0.1.0","engine.io-parser@5.2.3","socket.io@4.7.5","4.7.5","4.7.4","4.7.3","4.7.2","4.7.1","4.7.0","4.6.2","4.6.1","4.6.0","4.6.0-alpha1","4.5.4","4.5.3","4.5.2","4.5.1","4.5.0","4.4.1","4.4.0","4.3.2","4.3.1","4.3.0","4.2.0","4.1.3","4.1.2","4.1.1","4.1.0","4.0.2","4.0.1","4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-69185.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}