engine.io vulnerabilities
CVEs whose affected-version data names the engine.io package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-59725High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform
Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Ty…
▾ Twilightsocket · engine.ioEPSS 0.64%via NVD
CVE-2026-59724High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of th…
▾ Twilightsocket · engine.ioEPSS 0.61%via NVD