Socket has 3 CVEs on record. 3 were published in the last 90 days. The median CVSS is 7.5 (high). Most affected products: engine.io (2), socketdev/socket-registry-firewall (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
CVE-2026-90651High· 8.1Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default45CVE-2026-59725High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform41CVE-2026-59724High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform41
Socket vulnerabilities
CVEs affecting Socket, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-90651High· 8.1Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the …
CVE-2026-59725High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform
Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Ty…
CVE-2026-59724High· 7.5Socket.IO enables bidirectional and low-latency communication for every platform
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of th…