{"id":"GHSA-r635-g3xr-vw7x","summary":"Socket.IO: Engine.IO Polling Transport Connection Exhaustion","details":"### Impact\n\nAn unauthenticated remote attacker can cause a denial of service in affected versions of **engine.io** by opening Engine.IO polling sessions and sending an invalid binary `POST` request with:\n\n```\nContent-Type: application/octet-stream\n```\n\n\nagainst an Engine.IO protocol v4 polling transport.\n\nIn the vulnerable code path, the server reports a transport error but does not properly close the HTTP response associated with the malformed request. As a result, the underlying HTTP connection may remain open, consuming one server-side socket/resource per crafted request.\n\nAn attacker can repeat this with many sessions to exhaust available HTTP connections, sockets, file descriptors, or related server resources, potentially preventing legitimate clients from connecting.\n\n### Patches\n\nThe issue was fixed in:\n\n- **engine.io `6.6.7`**\n\nThe fix ensures that invalid binary polling `POST` requests are explicitly rejected with an HTTP response and closed properly.\n\nUsers should upgrade to:\n\n```sh\nnpm install engine.io@^6.6.7\n```\n\nor a later fixed version.\n\nIf using Socket.IO through the monorepo/packages, update to a Socket.IO release that depends on a fixed `engine.io` version.\n\n### Workarounds\n\nIf upgrading immediately is not possible, possible mitigations include:\n\n- Block or reject polling `POST` requests with `Content-Type: application/octet-stream` for Engine.IO protocol v4 at a reverse proxy, load balancer, WAF, or application middleware.\n- Disable HTTP long-polling if your deployment can use WebSocket-only transport.\n- Enforce strict request/connection timeouts at the HTTP server, reverse proxy, or load balancer.\n- Apply per-IP rate limits and connection limits for Engine.IO endpoints.\n- Restrict access to the Socket.IO/Engine.IO endpoint where feasible.\n\nExample Socket.IO configuration to disable polling, if compatible with your clients:\n\n```js\nconst io = new Server(httpServer, {\n  transports: [\"websocket\"],\n});\n```\n\n## References\n\n- Fix commit: https://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671\n- engine.io changelog entry for `6.6.7`: https://github.com/socketio/socket.io/blob/main/packages/engine.io/CHANGELOG.md#667-2026-04-27\n- socket.io repository: https://github.com/socketio/socket.io\n- engine.io package: https://www.npmjs.com/package/engine.io","aliases":["CVE-2026-59725"],"modified":"2026-09-10T03:51:11.922627169Z","published":"2026-07-20T21:49:54Z","database_specific":{"github_reviewed_at":"2026-07-20T21:49:54Z","nvd_published_at":"2026-07-08T16:16:33Z","cwe_ids":["CWE-404"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/socketio/socket.io/security/advisories/GHSA-r635-g3xr-vw7x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59725"},{"type":"WEB","url":"https://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671"},{"type":"PACKAGE","url":"https://github.com/socketio/socket.io"},{"type":"WEB","url":"https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7"}],"affected":[{"package":{"name":"engine.io","ecosystem":"npm","purl":"pkg:npm/engine.io"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.1.0"},{"fixed":"6.6.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r635-g3xr-vw7x/GHSA-r635-g3xr-vw7x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}