CVE-2026-102599 with a CVSS score of 7.5 is a vulnerability affecting engine.io versions These mitigations avoid the vulnerable upgrade path, but they may affect client compatibility and connection behavior affecting engine.io versions - `engine in Engine.IO / Socket.IO servers that allows transport upgrades, enabling a malicious client to establish a valid session and then send an upgrade request with a different or omitted EIO query parameter, causing the server to attach a transport using a parser and heartbeat behavior inconsistent with the session, potentially triggering an uncaught exception and terminating the Node.js process. Servers using the default Engine.IO v4 protocol are impacted. The issue can be triggered even when Engine.IO v3 compatibility is disabled. Affected versions include engine.io >= 6.6.0, < 6.6.10. This vulnerability leads to denial of service through process crash.
We recommend you to update engine.io to version 6.6.10.[/subscribe_to_unlock_form]
CVE-2026-102599 with a CVSS score of 7.5 is a vulnerability affecting engine.io versions These mitigations avoid the vulnerable upgrade path, but they may affect client compatibility and connection behavior affecting engine.io versions - `engine in Engine.IO / Socket.IO servers that allows transport upgrades, enabling a malicious client to establish a valid session and then send an upgrade request with a different or omitted EIO query parameter, causing the server to attach a transport using a parser and heartbeat behavior inconsistent with the session, potentially triggering an uncaught exception and terminating the Node.js process. Servers using the default Engine.IO v4 protocol are impacted. The issue can be triggered even when Engine.IO v3 compatibility is disabled. Affected versions include engine.io >= 6.6.0, < 6.6.10. This vulnerability leads to denial of service through process crash.
We recommend you to update engine.io to version 6.6.10.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]