{ "schema_version": "1.4.0", "id": "GHSA-r635-g3xr-vw7x", "modified": "2026-07-20T21:49:54Z", "published": "2026-07-20T21:49:54Z", "aliases": [ "CVE-2026-59725" ], "summary": "Socket.IO: Engine.IO Polling Transport Connection Exhaustion", "details": "### Impact\n\nAn unauthenticated remote attacker can cause a denial of service in affected versions of **engine.io** by opening Engine.IO polling sessions and sending an invalid binary `POST` request with:\n\n```\nContent-Type: application/octet-stream\n```\n\n\nagainst an Engine.IO protocol v4 polling transport.\n\nIn the vulnerable code path, the server reports a transport error but does not properly close the HTTP response associated with the malformed request. As a result, the underlying HTTP connection may remain open, consuming one server-side socket/resource per crafted request.\n\nAn attacker can repeat this with many sessions to exhaust available HTTP connections, sockets, file descriptors, or related server resources, potentially preventing legitimate clients from connecting.\n\n### Patches\n\nThe issue was fixed in:\n\n- **engine.io `6.6.7`**\n\nThe fix ensures that invalid binary polling `POST` requests are explicitly rejected with an HTTP response and closed properly.\n\nUsers should upgrade to:\n\n```sh\nnpm install engine.io@^6.6.7\n```\n\nor a later fixed version.\n\nIf using Socket.IO through the monorepo/packages, update to a Socket.IO release that depends on a fixed `engine.io` version.\n\n### Workarounds\n\nIf upgrading immediately is not possible, possible mitigations include:\n\n- Block or reject polling `POST` requests with `Content-Type: application/octet-stream` for Engine.IO protocol v4 at a reverse proxy, load balancer, WAF, or application middleware.\n- Disable HTTP long-polling if your deployment can use WebSocket-only transport.\n- Enforce strict request/connection timeouts at the HTTP server, reverse proxy, or load balancer.\n- Apply per-IP rate limits and connection limits for Engine.IO endpoints.\n- Restrict access to the Socket.IO/Engine.IO endpoint where feasible.\n\nExample Socket.IO configuration to disable polling, if compatible with your clients:\n\n```js\nconst io = new Server(httpServer, {\n transports: [\"websocket\"],\n});\n```\n\n## References\n\n- Fix commit: https://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671\n- engine.io changelog entry for `6.6.7`: https://github.com/socketio/socket.io/blob/main/packages/engine.io/CHANGELOG.md#667-2026-04-27\n- socket.io repository: https://github.com/socketio/socket.io\n- engine.io package: https://www.npmjs.com/package/engine.io", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], "affected": [ { "package": { "ecosystem": "npm", "name": "engine.io" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "4.1.0" }, { "fixed": "6.6.7" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/socketio/socket.io/security/advisories/GHSA-r635-g3xr-vw7x" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59725" }, { "type": "WEB", "url": "https://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671" }, { "type": "PACKAGE", "url": "https://github.com/socketio/socket.io" }, { "type": "WEB", "url": "https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7" } ], "database_specific": { "cwe_ids": [ "CWE-404" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2026-07-20T21:49:54Z", "nvd_published_at": "2026-07-08T16:16:33Z" } }