rpm package
opensuse/python-python-engineio&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/python-python-engineio&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48809 | Hig | 7.5 | < 4.12.0-bp160.2.1 | 4.12.0-bp160.2.1 | Aug 11, 2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att | |
| CVE-2026-48802 | Hig | 7.5 | < 4.12.0-bp160.2.1 | 4.12.0-bp160.2.1 | Aug 11, 2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when |
- affected < 4.12.0-bp160.2.1fixed 4.12.0-bp160.2.1
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att
- affected < 4.12.0-bp160.2.1fixed 4.12.0-bp160.2.1
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when