<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:socket.io:cluster-Engine:0.1.0:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asocket.iocluster-engine0.1.0node.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:45:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asocket.iocluster-engine0.1.0node.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Prototype Pollution in @socket.io/cluster-engine</title><link>https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/</link><pubDate>Tue, 06 Oct 2026 00:45:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-socketio-prototype-pollution/</guid><description>The @socket.io/cluster-engine package is vulnerable to prototype pollution when processing attacker-controlled session IDs, allowing an attacker to cause a denial of service via process crash.</description><content:encoded><![CDATA[<p>The @socket.io/cluster-engine package, used for managing socket connections in clustered environments, contains a prototype pollution vulnerability (CVE-2026-102600) in version 0.1.0. The vulnerability exists due to unsafe handling of client-provided session identifiers during the lookup process. An attacker can craft requests using special property names, such as '<strong>proto</strong>' or 'constructor', as session identifiers. Because the engine incorrectly treats these keys as valid session lookups, it attempts to access properties from the object prototype chain rather than the expected client storage objects. This unexpected state leads to internal server errors and, ultimately, a process crash, effectively resulting in a denial-of-service condition for affected Node.js applications. This issue specifically affects deployments utilizing the cluster-engine component.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in a denial of service (DoS) by crashing the Node.js process hosting the @socket.io/cluster-engine. This impact is significant for real-time applications relying on persistent socket connections, as the crash disrupts all connected clients on that process.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the @socket.io/cluster-engine package to version 0.1.1 or later to remediate CVE-2026-102600.</li>
<li>Implement input validation on session identifiers in custom middleware to reject keys containing '<strong>proto</strong>', 'constructor', or 'prototype' before passing them to the cluster engine as a defense-in-depth measure.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>nodejs</category><category>vulnerability</category><category>prototype-pollution</category><category>dos</category></item></channel></rss>