socket.io allows an unbounded number of binary attachments
Published Mar 20, 2026
8.7
HIGHCVSS 4.0
EPSS 0.63%
Description
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.
Affected products
-
- Version < 3.3.5StatusaffectedConstraints-
- Version >= 3.4.0, < 3.4.4StatusaffectedConstraints-
- Version >= 4.0.0, < 4.2.6StatusaffectedConstraints-
- Version
- < 3.3.5
- ≥ 3.4.0 · < 3.4.4
- ≥ 4.0.0 · < 4.2.6
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-operator-bundle
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-proxy-rhel9
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch-rhel9-operator
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/elasticsearch6-rhel9
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Fix deferred
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-curator5-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Fix deferred
Red Hat Fuse 7
io.syndesis-syndesis-parent
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-operator-bundle | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-proxy-rhel9 | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch-rhel9-operator | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/elasticsearch6-rhel9 | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Fix deferred | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-curator5-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Fix deferred | n/a |
| Red Hat Fuse 7 | io.syndesis-syndesis-parent | Fix deferred | n/a |
socket.io-parser
npm
Introduced 0 Fixed 3.3.5socket.io-parser
npm
Introduced 3.4.0 Fixed 3.4.4socket.io-parser
npm
Introduced 4.0.0 Fixed 4.2.6
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | socket.io-parser | 0 | 3.3.5 |
| npm | socket.io-parser | 3.4.0 | 3.4.4 |
| npm | socket.io-parser | 4.0.0 | 4.2.6 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-33151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2449789 Issue Tracking
- https://github.com/advisories/GHSA-677m-j7p3-52f9 Advisory
- https://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4 x_refsource_MISCPatch
- https://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf x_refsource_MISCPatch
- https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78 x_refsource_MISCPatch
- https://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9 x_refsource_CONFIRMPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-33151
- https://www.cve.org/CVERecord?id=CVE-2026-33151
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-33151 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2449789 | Issue Tracking | |
| https://github.com/advisories/GHSA-677m-j7p3-52f9 | Advisory | |
| https://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4 | x_refsource_MISCPatch | |
| https://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf | x_refsource_MISCPatch | |
| https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78 | x_refsource_MISCPatch | |
| https://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9 | x_refsource_CONFIRMPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-33151 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-33151 |
Change history (0)
No recorded changes yet.