HIGH 7.5 GitHub
CVE-2026-102599
Socket.IO: Engine.IO Protocol Revision Mismatch DoS
### Impact
A denial-of-service vulnerability exists in Engine.IO / Socket.IO servers that allow transport upgrades.
The Engine.IO protocol revision is negotiated during the initial handshake and stored on the session, but a newly-created transport, including a WebSocket upgrade transport, could independently derive a different protocol revision from the upgrade request query parameters. The server did not verify that the protocol revision of an upgrade request matched the protocol revision of
Affected Products
- npm/engine.io >= 6.6.0, < 6.6.10
References
- https://github.com/advisories/GHSA-2gc4-cqfq-p2gv
- https://github.com/socketio/socket.io/security/advisories/GHSA-2gc4-cqfq-p2gv
- https://github.com/socketio/socket.io/commit/86db1fc3db2cd315a065d64c4e48918ccf9b4729
- https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.10
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-29 via GitHub. Affected: npm/engine.io >= 6.6.0, < 6.6.10.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.