CVE-2026-69185: Socket.IO: Zero-attachment Memory Exhaustion
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
References
- github.com/advisories/GHSA-2m8v-j782-fhvr
- github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4
- github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240
- github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291
- github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
- nvd.nist.gov/vuln/detail/CVE-2026-69185
Code Behaviors & Features
Detect and mitigate CVE-2026-69185 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →