CVE-2026-59724
EUVD-2026-4231208.07.2026, 16:16
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| socket | engine.io | 6.5.0 ≤ 𝑥 < 6.6.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration