A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
| Version range | Used by | Fixed version |
|---|---|---|
>=4.0.0 <4.2.6 |
[email protected] and [email protected] |
4.2.6 |
>=3.4.0 <3.4.4 |
[email protected] |
3.4.4 |
<3.3.5 |
[email protected] |
3.3.5 |
There is no known workaround except upgrading to a safe version.
If you have any questions or comments about this advisory:
| Score | Percentile |
|---|---|
| 0.17% | 38.48% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-677m-j7p3-52f9 ↗ |
| CVE | CVE-2026-33151 ↗ |
| CWE id | Name |
|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | socket.io-parser | < 3.3.5 | 3.3.5 | — |
| npm | socket.io-parser | >= 3.4.0, < 3.4.4 | 3.4.4 | — |
| npm | socket.io-parser | >= 4.0.0, < 4.2.6 | 4.2.6 | — |