Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2m8v-j782-fhvr | Socket.IO: Zero-attachment Memory Exhaustion |
Fri, 07 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 05 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Socket
Socket socket.io |
|
| Vendors & Products |
Socket
Socket socket.io |
Mon, 03 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6. | |
| Title | Socket.IO: Zero-attachment Memory Exhaustion | |
| Weaknesses | CWE-20 CWE-754 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-03T20:31:54.428Z
Reserved: 2026-08-03T16:00:23.482Z
Link: CVE-2026-69185
Updated: 2026-08-03T20:31:46.564Z
Status : Received
Published: 2026-08-03T20:17:29.797
Modified: 2026-08-03T21:16:41.857
Link: CVE-2026-69185
OpenCVE Enrichment
Updated: 2026-08-07T02:15:04Z
Github GHSA