{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/engine.io--6.6.0--6.6.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:socket.io:engine.io:*:*:*:*:*:node.js:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["engine.io (\u003e= 6.6.0, \u003c 6.6.10)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Socket.IO"],"content_html":"\u003cp\u003eEngine.IO, the underlying engine for Socket.IO, contains a denial-of-service (DoS) vulnerability tracked as CVE-2026-102599. The flaw arises from insufficient validation of the Engine.IO (EIO) protocol revision during transport upgrades. When a client initiates an upgrade - such as moving from HTTP polling to a WebSocket transport - the server fails to verify that the protocol revision of the upgrade request matches the version negotiated during the initial session handshake.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by establishing a legitimate session and then sending a transport upgrade request with a mismatched or omitted \u003ccode\u003eEIO\u003c/code\u003e query parameter. Because the server inconsistently attaches a new transport with a different parser or heartbeat mechanism based on the malformed request, a subsequent crafted heartbeat packet can trigger an uncaught exception, leading to an immediate crash of the Node.js process. This vulnerability affects Engine.IO versions 6.6.0 through 6.6.9 and is present regardless of whether v3 compatibility is enabled.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete denial-of-service by crashing the Node.js process hosting the Socket.IO server. This impact is significant for real-time applications, potentially affecting all connected users and requiring manual service restarts. The scope of targeting includes any application relying on the vulnerable versions of Engine.IO exposed to public network traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eengine.io\u003c/code\u003e package to version 6.6.10 or later immediately to resolve the underlying validation logic error associated with CVE-2026-102599.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not feasible, update the Socket.IO server configuration to disable transport upgrades by setting \u003ccode\u003eallowUpgrades: false\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAlternatively, restrict allowed transports to \u003ccode\u003e['websocket']\u003c/code\u003e only to bypass the vulnerable upgrade path.\u003c/li\u003e\n\u003cli\u003eImplement application-layer middleware to reject requests containing a session ID (sid) where the \u003ccode\u003eEIO\u003c/code\u003e parameter is missing or inconsistent with the initial session handshake version.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T04:19:03Z","date_published":"2026-09-30T04:19:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-socket-io-dos/","summary":"A denial-of-service vulnerability in Engine.IO versions 6.6.0 through 6.6.9 allows remote attackers to crash Node.js processes by sending crafted WebSocket upgrade requests with mismatched protocol parameters.","title":"Engine.IO Protocol Revision Mismatch Denial of Service","url":"https://feed.craftedsignal.io/briefs/2026-09-socket-io-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Engine.io (\u003e= 6.6.0, \u003c 6.6.10)","version":"https://jsonfeed.org/version/1.1"}