CyberRota Analysis
AI-GeneratedEngine.IO servers using Socket.IO versions 6.5.0 to 6.6.6 with WebTransport enabled are vulnerable to a denial-of-service attack due to improper handling of crafted session IDs, which can trigger a TypeError. This vulnerability can disrupt service availability, making it critical for organizations utilizing affected versions to upgrade to 6.6.7 immediately to mitigate potential impacts. Users of Socket.IO in production environments should prioritize this update to ensure system stability and security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.
Related CVEs
Other vulnerabilities affecting the same vendor(s)