Junglewise Threat Intelligence

CVE-2026-33151: Socket.IO denial of service via unbounded binary attachments

CVE-2026-33151 · Severity: medium · CVSS 4 · Published 2026-03-18

Executive brief

Socket.IO is a library that enables real-time bidirectional communication between web clients and servers. A vulnerability in its packet parser allows an attacker to send a specially crafted message with an unbounded number of binary attachments, causing the server to buffer them indefinitely and exhaust available memory. This can render the application unavailable and disrupt services for legitimate users.

Technical details

The vulnerability is an improper input validation issue (CWE-20, CWE-754) in socket.io-parser's handling of binary attachments in Socket.IO protocol messages. A crafted packet can declare a very large number of binary attachments without actually sending them, forcing the server to wait and buffer them indefinitely. An unauthenticated attacker on the network can exploit this by sending malicious packets to any socket.io server, leading to memory exhaustion and denial of service. Patches are available in socket.io-parser versions 3.3.5, 3.4.4, and 4.2.6, with corresponding fixes in socket.io itself.

Affected products

  • Socket.IO socket.io-parser <3.3.5, >=3.4.0 <3.4.4, >=4.0.0 <4.2.6
  • Socket.IO socket.io 4.x <4.2.6, 2.x <3.4.4 (via socket.io-parser)
  • Socket.IO socket.io-client 4.x <4.2.6, 2.x <3.3.5

Timeline

  • 2026-03-18: disclosed: Advisory published on GitHub and OSV
  • 2026-03-18: patched: Patches released: socket.io-parser 3.3.5, 3.4.4, 4.2.6

References

Related threats