CVE-2026-59724 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting Engine.IO. Servers with WebTransport enabled allow an unauthenticated remote attacker to crash the server process and cause denial of service by sending a crafted WebTransport upgrade request containing a specially chosen session ID. The issue occurs due to improper verification of the session ID lookup, which can resolve to an inherited prototype property instead of a valid Engine.IO client, resulting in a TypeError during WebTransport upgrade handling. Successful exploitation may allow repeated crash loops under a process supervisor. The vulnerability falls under the network attack vector. The business impact is significant, as successful exploitation can cause service disruption and denial of service.
We recommend you to update engine.io to version 6.6.9 or later.[/subscribe_to_unlock_form]
CVE-2026-59724 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting Engine.IO. Servers with WebTransport enabled allow an unauthenticated remote attacker to crash the server process and cause denial of service by sending a crafted WebTransport upgrade request containing a specially chosen session ID. The issue occurs due to improper verification of the session ID lookup, which can resolve to an inherited prototype property instead of a valid Engine.IO client, resulting in a TypeError during WebTransport upgrade handling. Successful exploitation may allow repeated crash loops under a process supervisor. The vulnerability falls under the network attack vector. The business impact is significant, as successful exploitation can cause service disruption and denial of service.
We recommend you to update engine.io to version 6.6.9 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]