Threat Advisory

Zero-attachment Memory Exhaustion Flaw Allows Server Crash

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-69185 with a CVSS score of 7.5 is a vulnerability in the socket.io-parser package, specifically affecting versions >=4.0.0, <4.2.7, and versions >=3.4.0, <3.4.5, and versions <3.3.6, where a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory, allowing an attacker with network access to cause a denial-of-service condition by exhausting available system resources.

RECOMMENDATION:

We recommend you to update socket.io-parser to version 4.2.7 or 3.4.5 or 3.3.6 depending on your installed branch.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-69185 with a CVSS score of 7.5 is a vulnerability in the socket.io-parser package, specifically affecting versions >=4.0.0, <4.2.7, and versions >=3.4.0, <3.4.5, and versions <3.3.6, where a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory, allowing an attacker with network access to cause a denial-of-service condition by exhausting available system resources.

RECOMMENDATION:

We recommend you to update socket.io-parser to version 4.2.7 or 3.4.5 or 3.3.6 depending on your installed branch.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu