CVE-2026-59725Patch(socket / engine.io)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch socket engine.io systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • engine.io

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-07-09); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
engine.io

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 107-0907-1107-13
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
By indicator
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-59725 (CVSS 7.5) Socket[.]IO v4.1.0-6.6.6 vulnerable to connection exhaustion via malformed binary POST requests. Unauthenticated remote DoS possible. Patch to v6.6.7 immediately. #CVE #Vulnerability #PatchNow https://t.co/owCO7R2CZE

    Post summary

    The tweet announces a CVE-2026-59725 remote DoS in Socket.IO with a CVSS score of 7.5, provides critical patch information (v6.6.7), and contains no evidence of active exploitation or PoC.

    0000035
    71 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-59725 (CVSS 7.5) - Socket[.]IO vulnerability allows unauthenticated attackers to exhaust server connections via malformed POST requests. Affects v4.1.0-6.6.6. Patch to 6.6.7 immediately. #CVE #PatchNow https://t.co/dgCo1plLoX

    Post summary

    The tweet alerts to a high‑severity CVE‑2026‑59725 in Socket[.]IO that enables connection exhaustion and advises updating to version 6.6.7.

    0000043
    71 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - http://Socket.IO http://Engine.IO polling transport connection leak DoS (CVE-2026-59725) http://Socket.IO (http://Engine.IO protocol v4 polling transport) mishandles invalid binary POST requests sent with Content-Type: application/octet-stream, leaving HTTP responses improperly closed. The root cause is improper input handling/resource management leading to a connection/socket leak when parsing invalid binary payloads. An unauthenticated attacker can repeatedly send crafted invalid binary POSTs to the polling endpoint to keep server-side connections open and consume sockets. Successful exploitation results in denial of service by exhausting available connections/file descriptors, degrading or taking down real-time messaging for legitimate users. 👉 Affected: http://socket.io 4.1.0 to 6.6.6 | Upgrade to 6.6.7

    Post summary

    The post discloses a severe DoS vulnerability in Socket.IO’s polling transport, details the exploitation pathway, and instructs users to upgrade to 6.6.7 to mitigate.

    00000124
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsocketengine.io-node.js-

Explore more