CVE-2026-33151
HIGH7.5EPSS 0.05%socket.io allows an unbounded number of binary attachments
發布日:2026/3/18修改日:2026/4/28
描述
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.
受影響套件(2)
- Debian/node-socket.io-parserfrom 0
- npm/socket.io-parserfrom 0, < 3.3.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2026-33151
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2026-33151
- PATCHhttps://github.com/socketio/socket.io
- WEBhttps://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4
- WEBhttps://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf
- WEBhttps://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78
- WEBhttps://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9