VendorsSocketengine.ioall versions
Vulnerabilities

Socket Engine.IO

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-36048
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Published 2021-01-07 · Modified
7.5EPSS 0.032
CVE-2022-21676
Uncaught Exception in engine.io
Published 2022-01-12 · Modified
7.5EPSS 0.028
CVE-2026-59725
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2026-59724
Socket.IO: Engine.IO WebTransport SID DoS
Published 2026-07-08 · Analyzed
7.5EPSS 0.006
CVE-2022-41940
Uncaught exception in engine.io
Published 2022-11-22 · Modified
7.1EPSS 0.021
CVE-2023-31125
Uncaught exception in engine.io
Published 2023-05-08 · Modified
6.5EPSS 0.013