CVE-2026-33151

Updated on 18 Mar 2026

Severity

8.7 High severity

Details

CVSS score
8.7
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

Impact

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Patches

Version range Used by Fixed version
>=4.0.0 <4.2.6 [email protected] and [email protected] 4.2.6
>=3.4.0 <3.4.4 [email protected] 3.4.4
<3.3.5 [email protected] 3.3.5

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

  • Open a discussion here

Details

Affected packages:
socket.io-client @ 2.0.4 (+26 more)

Fixes