{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asocket.iocluster-engine0.1.0node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:socket.io:cluster-engine:0.1.0:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-102600"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cluster-engine (\u003c 0.1.1)"],"_cs_severities":["low"],"_cs_tags":["nodejs","vulnerability","prototype-pollution","dos"],"_cs_type":"advisory","_cs_vendors":["Socket.IO"],"content_html":"\u003cp\u003eThe @socket.io/cluster-engine package, used for managing socket connections in clustered environments, contains a prototype pollution vulnerability (CVE-2026-102600) in version 0.1.0. The vulnerability exists due to unsafe handling of client-provided session identifiers during the lookup process. An attacker can craft requests using special property names, such as '\u003cstrong\u003eproto\u003c/strong\u003e' or 'constructor', as session identifiers. Because the engine incorrectly treats these keys as valid session lookups, it attempts to access properties from the object prototype chain rather than the expected client storage objects. This unexpected state leads to internal server errors and, ultimately, a process crash, effectively resulting in a denial-of-service condition for affected Node.js applications. This issue specifically affects deployments utilizing the cluster-engine component.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a denial of service (DoS) by crashing the Node.js process hosting the @socket.io/cluster-engine. This impact is significant for real-time applications relying on persistent socket connections, as the crash disrupts all connected clients on that process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @socket.io/cluster-engine package to version 0.1.1 or later to remediate CVE-2026-102600.\u003c/li\u003e\n\u003cli\u003eImplement input validation on session identifiers in custom middleware to reject keys containing '\u003cstrong\u003eproto\u003c/strong\u003e', 'constructor', or 'prototype' before passing them to the cluster engine as a defense-in-depth measure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:45:04Z","date_published":"2026-10-06T00:45:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/","summary":"The @socket.io/cluster-engine package is vulnerable to prototype pollution when processing attacker-controlled session IDs, allowing an attacker to cause a denial of service via process crash.","title":"Prototype Pollution in @socket.io/cluster-engine","url":"https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:socket.io:cluster-Engine:0.1.0:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}