cvedb.io
CVE-2026-33151
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-03-20T21:17:15.573 · Last modified 2026-06-17T10:37:02.107

Summary

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This issue has been patched in versions 3.3.5, 3.4.4, and 4.2.6.

Affected products

socket — socket.io-parser

Does this affect you?

Add your gear to cvedb and we'll alert you only when socket ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.