Answer in brief
CVE-2026-69185 records a High severity security vulnerability in Socket.IO: Zero-attachment Memory Exhaustion. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
Answer in brief
CVE-2026-69185 records a High severity security vulnerability in Socket.IO: Zero-attachment Memory Exhaustion. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
Update socket.io-parser to 4.2.7; socket.io-parser to 3.4.5; socket.io-parser to 3.3.6 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-69185 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| socket.io-parsernpm | >=4.0.0,<4.2.7 | 4.2.7 |
| socket.io-parsernpm | >=3.4.0,<3.4.5 | 3.4.5 |
| socket.io-parsernpm | <3.3.6 | 3.3.6 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-69185 records a High severity security vulnerability in Socket.IO: Zero-attachment Memory Exhaustion. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for socket.io-parser, socket.io-parser, socket.io-parser.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate socket.io-parser to 4.2.7; socket.io-parser to 3.4.5; socket.io-parser to 3.3.6 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-69185 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| socket.io-parsernpm | >=4.0.0,<4.2.7 | 4.2.7 |
| socket.io-parsernpm | >=3.4.0,<3.4.5 | 3.4.5 |
| socket.io-parsernpm | <3.3.6 | 3.3.6 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-69185 records a High severity security vulnerability in Socket.IO: Zero-attachment Memory Exhaustion. The source record does not mark it as known exploited. 3 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for socket.io-parser, socket.io-parser, socket.io-parser.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard### Impact A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. ### Patches | Version range | Used by | Fixed version | |------------------|--------------------------------------------|---------------| | `>=4.0.0 <4.2.7` | `[email protected]` and `[email protected]` | `4.2.7` | | `>=3.4.0 <3.4.5` | `[email protected]` | `3.4.5` | | `<3.3.6` | `[email protected]` | `3.3.6` | ### Workarounds There is no known workaround except upgrading to a safe version. ### For more information If you have any questions or comments about this advisory: - Open a discussion [here](https://github.com/socketio/socket.io/discussions)
### Impact A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. ### Patches | Version range | Used by | Fixed version | |------------------|--------------------------------------------|---------------| | `>=4.0.0 <4.2.7` | `[email protected]` and `[email protected]` | `4.2.7` | | `>=3.4.0 <3.4.5` | `[email protected]` | `3.4.5` | | `<3.3.6` | `[email protected]` | `3.3.6` | ### Workarounds There is no known workaround except upgrading to a safe version. ### For more information If you have any questions or comments about this advisory: - Open a discussion [here](https://github.com/socketio/socket.io/discussions)