Product
A denial-of-service vulnerability in Engine.IO versions 6.6.0 through 6.6.9 allows remote attackers to crash Node.js processes by sending crafted WebSocket upgrade requests with mismatched protocol parameters.