6.5
CVSSv3

CVE-2022-41940

Published: 22/11/2022 Updated: 26/11/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

socket engine.io

Vendor Advisories

Synopsis Critical: Red Hat Fuse 712 release and security update Type/Severity Security Advisory: Critical Topic A minor version update (from 711 to 712) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update as h ...
DescriptionThe MITRE CVE dictionary describes this issue as: EngineIO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for SocketIO A specially crafted HTTP request can trigger an uncaught exception on the EngineIO server, thus killing the Nodejs process This impacts all the users of the e ...