CVE-2026-59724Patch(socket / engine.io)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch socket engine.io systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • engine.io

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-13); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
engine.io

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-11: 1Mentions · 2026-07-13: 2Mentions · 2026-09-02: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-13: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 2Technical Details · 2026-09-02: 107-1107-1309-02
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-111
Patch1
2026-07-132
Disclosure1Patch1
2026-09-021
Patch1
Full discourse4 posts
  • Charz🍃@charrz__
    Patch

    https://secalerts.co/vulnerability/CVE-2026-59724

    Post summary

    The alert provides technical details of CVE‑2026‑59724 and directs readers to apply the vendor‑released patch to mitigate the remote code execution risk.

    00010101
    2.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 SocketIO (EngineIO) WebTransport Prototype Pollution Denial-of-Service Vulnerability (#CVE-2026-59724) - High -DC-Jul2026-918 https://dailycve.com/socketio-engineio-webtransport-prototype-pollution-denial-of-service-vulnerability-cve-2026-59724-high-dc-jul2026-918/

    Post summary

    The tweet announces a new high‑severity CVE identifying a prototype pollution denial‑of‑service flaw in SocketIO (EngineIO). It contains basic technical details but no exploitation, patch, or PoC information.

    0000050
    218 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-59724 (CVSS 7.5) Socket[.]IO Engine[.]IO servers with WebTransport enabled vulnerable to DoS via crafted session ID exploitation. Affects v6.5.0-6.6.6. ✅ Patch: Upgrade to v6.6.7 #CVE #Vulnerability #PatchNow https://t.co/4OaTVBcjM3

    Post summary

    The post announces CVE-2026-59724, details a DoS vulnerability in Socket.IO Engine.IO servers, and provides a clear patch recommendation to upgrade to v6.6.7.

    0000058
    71 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-59724 (CVSS 7.5) Socket[.]IO/Engine[.]IO DoS vulnerability affects versions 6.5.0-6.6.6 with WebTransport enabled. Crafted session IDs cause TypeError crashes. ✅ Patch: Update to v6.6.7 #CVE #Vulnerability #PatchNow https://t.co/zZkqfgINQq

    Post summary

    A high‑severity DoS vulnerability (CVE‑2026‑59724) in Socket.IO/Engine.IO versions 6.5.0‑6.6.6 with WebTransport enabled is patched by updating to v6.6.7.

    0000050
    71 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsocketengine.io-node.js-

Explore more