Threat Advisory

Engine.IO Vulnerability Triggers Process Shutdown After Improper Property Lookup

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59724 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting Engine.IO. Servers with WebTransport enabled allow an unauthenticated remote attacker to crash the server process and cause denial of service by sending a crafted WebTransport upgrade request containing a specially chosen session ID. The issue occurs due to improper verification of the session ID lookup, which can resolve to an inherited prototype property instead of a valid Engine.IO client, resulting in a TypeError during WebTransport upgrade handling. Successful exploitation may allow repeated crash loops under a process supervisor. The vulnerability falls under the network attack vector. The business impact is significant, as successful exploitation can cause service disruption and denial of service.

RECOMMENDATION:

We recommend you to update engine.io to version 6.6.9 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-59724 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting Engine.IO. Servers with WebTransport enabled allow an unauthenticated remote attacker to crash the server process and cause denial of service by sending a crafted WebTransport upgrade request containing a specially chosen session ID. The issue occurs due to improper verification of the session ID lookup, which can resolve to an inherited prototype property instead of a valid Engine.IO client, resulting in a TypeError during WebTransport upgrade handling. Successful exploitation may allow repeated crash loops under a process supervisor. The vulnerability falls under the network attack vector. The business impact is significant, as successful exploitation can cause service disruption and denial of service.

RECOMMENDATION:

We recommend you to update engine.io to version 6.6.9 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu