CPE
A vulnerability in Engine.IO versions 6.5.0 through 6.6.6 allows unauthenticated attackers to cause a process crash by sending a crafted WebTransport upgrade request.