{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/engine.io--6.5.0--6.6.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:socket.io:engine.io:*:*:*:*:*:node.js:*:*","cpe:2.3:a:socket:engine.io:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-59724"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["engine.io (\u003e= 6.5.0 \u003c 6.6.7)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Socket.IO"],"content_html":"\u003cp\u003eThe Engine.IO library, a core component for real-time communication in Socket.IO applications, contains a denial of service (DoS) vulnerability (CVE-2026-59724) affecting deployments where WebTransport support is explicitly enabled. The vulnerability stems from improper validation of session ID lookups in the WebTransport upgrade handshake. An unauthenticated remote attacker can submit a crafted upgrade request with a session ID value like \u0026quot;\u003cstrong\u003eproto\u003c/strong\u003e\u0026quot;. Because the server fails to verify that the key is an own property of the clients object, the lookup resolves to an inherited prototype property, triggering a TypeError. This error, occurring in an asynchronous context, leads to an unhandled Promise rejection that terminates the Node.js process. This vulnerability affects Engine.IO versions 6.5.0 up to 6.6.6. Defenders should prioritize upgrading to version 6.6.7 or disabling WebTransport support if the immediate upgrade is not feasible.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate termination of the Engine.IO server process. In production environments without robust process supervision, this causes a total loss of service. If a process supervisor is present, repeated exploitation by an attacker will result in continuous crash loops, effectively preventing service availability for legitimate users. This threat specifically targets web applications using the Node.js ecosystem and real-time Socket.IO communication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Engine.IO dependency to version 6.6.7 or later to patch CVE-2026-59724.\u003c/li\u003e\n\u003cli\u003eIf upgrading is delayed, immediately modify the Engine.IO configuration to remove \u0026quot;webtransport\u0026quot; from the enabled transports list.\u003c/li\u003e\n\u003cli\u003eMonitor server logs for repeated process crashes or unusual WebTransport upgrade requests containing prototype manipulation keys.\u003c/li\u003e\n\u003cli\u003eInspect HTTP/3 and WebTransport gateway traffic at the reverse proxy layer for anomalous session ID formatting.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T23:58:36Z","date_published":"2026-08-31T23:58:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-engineio-dos/","summary":"A vulnerability in Engine.IO versions 6.5.0 through 6.6.6 allows unauthenticated attackers to cause a process crash by sending a crafted WebTransport upgrade request.","title":"Engine.IO WebTransport Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-08-engineio-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Engine.io (\u003e= 6.5.0 \u003c 6.6.7)","version":"https://jsonfeed.org/version/1.1"}