HIGH
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
Published Sep 29, 2026
7.5
HIGHCVSS 3.1
Description
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
engine.io
npm
Introduced 6.6.0 Fixed 6.6.10
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | engine.io | 6.6.0 | 6.6.10 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
7.5 HIGH GHSA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-2gc4-cqfq-p2gv Advisory
- https://github.com/socketio/socket.io/commit/86db1fc3db2cd315a065d64c4e48918ccf9b4729
- https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.10
- https://github.com/socketio/socket.io/security/advisories/GHSA-2gc4-cqfq-p2gv
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 29, 2026
Updated n/a
Reserved n/a
Link CVE-2026-102599
CISA Vulnrichment
GHSA-2GC4-CQFQ-P2GV Updated n/a