---
id: CVE-2026-48804
title: >-
  python-socketio is a Python implementation of the Socket.IO realtime client
  and server
summary: >-
  python-socketio is a Python implementation of the Socket.IO realtime client
  and server. The python-socketio server stores binary `EVENT` and `ACK`
  messages in memory while it waits to receive their binary attachments. Once
  all the attach…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: python-socketio
product: python-socketio
affected:
  - python-socketio <= 5.16.1
patched:
  - python-socketio 5.16.2
published: '2026-08-11'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T20:30:11.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48804'
references:
  - url: >-
      https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e
    label: security-advisories@github.com
  - url: >-
      https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-5w7q-77mv-v69f'
tags:
  - nvd
  - ghsa
  - pip
epss: 0.00279
epssPercentile: 0.20617
ecosystem: pip
ingestedAt: '2026-06-29T13:24:35.263Z'
---

## Overview

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-48804)

Affected packages:

- `python-socketio <= 5.16.1`

Patched in:

- `python-socketio 5.16.2`

Source: https://github.com/advisories/GHSA-5w7q-77mv-v69f
