rpm package
opensuse/python-python-engineio&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/python-python-engineio&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-48809 | Hig | 7.5 | < 4.13.3-1.1 | 4.13.3-1.1 | Aug 11, 2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att | |
| CVE-2019-13611 | Hig | 8.8 | < 4.3.4-3.3 | 4.3.4-3.3 | Jul 16, 2019 | An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted. |
- affected < 4.13.3-1.1fixed 4.13.3-1.1
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att
- affected < 4.3.4-3.3fixed 4.3.4-3.3
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.