AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-59724

HIGH · CVSS 7.5 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

Engine.IO servers using Socket.IO versions 6.5.0 to 6.6.6 with WebTransport enabled are vulnerable to a denial-of-service attack due to improper handling of crafted session IDs, which can trigger a TypeError. This vulnerability can disrupt service availability, making it critical for organizations utilizing affected versions to upgrade to 6.6.7 immediately to mitigate potential impacts. Users of Socket.IO in production environments should prioritize this update to ensure system stability and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59724
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.

Related CVEs

Other vulnerabilities affecting the same vendor(s)