{"id":"CVE-2026-59724","title":"Socket.IO enables bidirectional and low-latency communication for every platform","summary":"Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"socket","product":"engine.io","affected":["engine.io >= 6.5.0, < 6.6.7"],"patched":["engine.io 6.6.7"],"published":"2026-07-08","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59724","references":[{"url":"https://github.com/socketio/socket.io/commit/1fa1f46cd420ac5b57bb4c04c959b58f3c79158c","label":"security-advisories@github.com"},{"url":"https://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7","label":"security-advisories@github.com"},{"url":"https://github.com/socketio/socket.io/security/advisories/GHSA-gr94-w7qr-f4j3","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00609,"epssPercentile":0.47854,"ingestedAt":"2026-07-13T15:27:34.115Z","slug":"CVE-2026-59724","body":"## Overview\n\nSocket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.\n\n## Affected\n\n- `engine.io >= 6.5.0, < 6.6.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `engine.io 6.6.7`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}