Vulnerabilities
Vulnerable Software
Socket:  >> Engine.io  >> 1.6.10  Security Vulnerabilities
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.
CVSS Score
7.1
EPSS Score
0.029
Published
2022-11-22
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
CVSS Score
7.5
EPSS Score
0.008
Published
2021-01-08


Contact Us

Shodan ® - All rights reserved