High severity7.5OSV Advisory· Published Jul 8, 2026· Updated Jul 13, 2026
CVE-2026-59725
CVE-2026-59725
Description
Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
engine.ionpm | >= 4.1.0, < 6.6.7 | 6.6.7 |
Affected products
5[email protected], [email protected], [email protected], …+ 1 more
- (no CPE)range: [email protected], [email protected], [email protected], …
- (no CPE)range: 4.1.0 <= v < 6.6.7
- osv-coords2 versions
< 3.8.0-r1+ 1 more
- (no CPE)range: < 3.8.0-r1
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
5- github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671nvdPatchWEB
- github.com/socketio/socket.io/security/advisories/GHSA-r635-g3xr-vw7xnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-r635-g3xr-vw7xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59725ghsaADVISORY
- github.com/socketio/socket.io/releases/tag/[email protected]nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.