CyberRota Analysis
AI-GeneratedSocket.IO versions prior to 4.2.7, 3.4.5, and 3.3.6 are vulnerable to a denial-of-service attack where specially crafted packets can cause the server to exhaust its memory by queuing excessive binary attachments. This can lead to service disruption and degraded performance. Organizations using affected versions should prioritize patching to mitigate the risk of potential outages.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.