{"id":"GHSA-wfpm-5gcm-94cg","summary":"Socket.IO: Prototype Pollution via Unsafe Client Session Lookup","details":"### Impact\n\nThis is a **prototype pollution / improper client lookup** vulnerability in `@socket.io/cluster-engine`.\n\nServers using `@socket.io/cluster-engine` may be impacted when attacker-controlled session IDs are processed in clustered deployments. A malicious client could use special property names such as `__proto__`, `constructor`, or other inherited object keys as a session identifier, causing the server to read properties from the object prototype chain instead of only real connected clients.\n\nThe impact is **denial of service** through process crash.\n\nApplications not using `@socket.io/cluster-engine` are not affected by this specific issue.\n\nAffected versions:\n\n*  `@socket.io/cluster-engine@0.1.0`\n\n### Patches\n\nThe issue was fixed in:\n\n*  `@socket.io/cluster-engine@0.1.1`\n\n### Workarounds\n\nIf upgrading immediately is not possible, users can reduce exposure by:\n\n- Rejecting or sanitizing suspicious session IDs before they reach the cluster engine.\n- Running the cluster engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests.\n\nThese workarounds are defense-in-depth only. Upgrading to a patched version is recommended.","aliases":["CVE-2026-102600"],"modified":"2026-10-06T00:00:08.444830774Z","published":"2026-10-05T23:44:21Z","database_specific":{"github_reviewed_at":"2026-10-05T23:44:21Z","nvd_published_at":"2026-09-29T16:17:06Z","cwe_ids":["CWE-20"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/socketio/socket.io/security/advisories/GHSA-wfpm-5gcm-94cg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102600"},{"type":"WEB","url":"https://github.com/socketio/socket.io/commit/830e3642ebb8dc3784eb749b0a004fe2b932b429"},{"type":"PACKAGE","url":"https://github.com/socketio/socket.io"},{"type":"WEB","url":"https://github.com/socketio/socket.io/releases/tag/@socket.io/cluster-engine@0.1.1"}],"affected":[{"package":{"name":"@socket.io/cluster-engine","ecosystem":"npm","purl":"pkg:npm/%40socket.io/cluster-engine"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wfpm-5gcm-94cg/GHSA-wfpm-5gcm-94cg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}