Skip to content
Threat Feed
low advisory

Prototype Pollution in @socket.io/cluster-engine

The @socket.io/cluster-engine package is vulnerable to prototype pollution when processing attacker-controlled session IDs, allowing an attacker to cause a denial of service via process crash.

CVE search metadata

CVE search record: CVE-2026-102600. Severity: high. CVSS: 7.5. EPSS: 0.37%. KEV: no. Product: cluster-engine (< 0.1.1). Brief: Prototype Pollution in @socket.io/cluster-engine. Brief link: https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/

The @socket.io/cluster-engine package, used for managing socket connections in clustered environments, contains a prototype pollution vulnerability (CVE-2026-102600) in version 0.1.0. The vulnerability exists due to unsafe handling of client-provided session identifiers during the lookup process. An attacker can craft requests using special property names, such as 'proto' or 'constructor', as session identifiers. Because the engine incorrectly treats these keys as valid session lookups, it attempts to access properties from the object prototype chain rather than the expected client storage objects. This unexpected state leads to internal server errors and, ultimately, a process crash, effectively resulting in a denial-of-service condition for affected Node.js applications. This issue specifically affects deployments utilizing the cluster-engine component.

Impact

The vulnerability results in a denial of service (DoS) by crashing the Node.js process hosting the @socket.io/cluster-engine. This impact is significant for real-time applications relying on persistent socket connections, as the crash disrupts all connected clients on that process.

Recommendation

  • Upgrade the @socket.io/cluster-engine package to version 0.1.1 or later to remediate CVE-2026-102600.
  • Implement input validation on session identifiers in custom middleware to reject keys containing 'proto', 'constructor', or 'prototype' before passing them to the cluster engine as a defense-in-depth measure.

Immediate actions

Upgrade @socket.io/cluster-engine to 0.1.1 or later

Development 48h

Mitigations

Implement input sanitization for session IDs to reject prototype-pollution-related keys

immediate Development

CVE-2026-102600