Prototype Pollution in @socket.io/cluster-engine
The @socket.io/cluster-engine package is vulnerable to prototype pollution when processing attacker-controlled session IDs, allowing an attacker to cause a denial of service via process crash.
CVE search metadata
CVE search record: CVE-2026-102600. Severity: high. CVSS: 7.5. EPSS: 0.37%. KEV: no. Product: cluster-engine (< 0.1.1). Brief: Prototype Pollution in @socket.io/cluster-engine. Brief link: https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/
The @socket.io/cluster-engine package, used for managing socket connections in clustered environments, contains a prototype pollution vulnerability (CVE-2026-102600) in version 0.1.0. The vulnerability exists due to unsafe handling of client-provided session identifiers during the lookup process. An attacker can craft requests using special property names, such as 'proto' or 'constructor', as session identifiers. Because the engine incorrectly treats these keys as valid session lookups, it attempts to access properties from the object prototype chain rather than the expected client storage objects. This unexpected state leads to internal server errors and, ultimately, a process crash, effectively resulting in a denial-of-service condition for affected Node.js applications. This issue specifically affects deployments utilizing the cluster-engine component.
Impact
The vulnerability results in a denial of service (DoS) by crashing the Node.js process hosting the @socket.io/cluster-engine. This impact is significant for real-time applications relying on persistent socket connections, as the crash disrupts all connected clients on that process.
Recommendation
- Upgrade the @socket.io/cluster-engine package to version 0.1.1 or later to remediate CVE-2026-102600.
- Implement input validation on session identifiers in custom middleware to reject keys containing 'proto', 'constructor', or 'prototype' before passing them to the cluster engine as a defense-in-depth measure.
Immediate actions
Upgrade @socket.io/cluster-engine to 0.1.1 or later
Mitigations
Implement input sanitization for session IDs to reject prototype-pollution-related keys
CVE-2026-102600