Vulnerability DatabaseCVE-2026-102599

CVE-2026-102599: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-102599 is a denial-of-service vulnerability in the Engine.IO / Socket.IO npm package, named "Engine.IO Protocol Revision Mismatch DoS." It affects engine.io versions >= 6.6.0 and < 6.6.10, and was first published by maintainer darrachequesne on September 14, 2026, with the advisory added to the GitHub Advisory Database on September 29, 2026. The vulnerability allows an unauthenticated remote attacker to crash the Node.js server process by exploiting a protocol revision mismatch during WebSocket transport upgrades. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Socket.IO Advisory).

Technical details

The root cause is an uncaught exception (CWE-248) triggered by a missing validation step: the server failed to verify that the EIO query parameter in a WebSocket upgrade request matched the protocol revision negotiated during the initial session handshake. Each transport independently computed its protocol revision from the request's query parameters, while the session stored its own pinned revision. An attacker could establish a legitimate Engine.IO v4 session (via polling with EIO=4) and then send a WebSocket upgrade request with a mismatched or omitted EIO parameter — an omitted parameter defaults to protocol v3 on the upgrade path — causing the server to attach a transport with an incompatible parser and heartbeat mode. Under these conditions, a crafted heartbeat packet triggers an uncaught exception that terminates the Node.js process. The fix, applied in commit 86db1fc, introduces a computeProtocolRevision() helper and rejects upgrade requests where the derived protocol does not match the session's pinned protocol (Socket.IO Advisory, Fix Commit).

Impact

Successful exploitation results in a complete denial of service through an unhandled Node.js process crash, making the server unavailable to all connected clients. There is no confidentiality or integrity impact — the vulnerability is purely an availability issue. Because a single unauthenticated request sequence can crash the entire Node.js process, all Socket.IO/Engine.IO sessions on the affected server are terminated simultaneously, and the service remains unavailable until the process is restarted (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory publication date. The vulnerability requires no privileges and no user interaction, and is reachable over the network with low attack complexity, making it straightforward to exploit by any network-accessible attacker against a vulnerable server. The CVE status is listed as "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. The reporter credited is sondt99 (GitHub Advisory, Socket.IO Advisory).

Exploitation steps

  1. Identify target: Locate a publicly accessible Node.js server running Socket.IO or Engine.IO with engine.io >= 6.6.0 and < 6.6.10 that permits transport upgrades (the default configuration).
  2. Establish a valid session: Send an HTTP GET polling request with EIO=4 to initiate a handshake and obtain a valid session ID (sid): GET /engine.io/?transport=polling&EIO=4
  3. Send a mismatched upgrade request: Using the obtained sid, send a WebSocket upgrade request with a mismatched or omitted EIO parameter (e.g., EIO=3 or no EIO at all): ws://target/engine.io/?transport=websocket&sid=<SID> (omitting EIO or setting EIO=3)
  4. Trigger the crash: Once the server attaches the WebSocket transport with an inconsistent parser/heartbeat mode, send a crafted heartbeat packet that is valid for one protocol version but invalid for the other. This triggers an uncaught exception in the Node.js process, crashing the server and terminating all active connections (Socket.IO Advisory, Fix Commit).

Indicators of compromise

  • Network: Repeated HTTP GET requests to /engine.io/?transport=polling&EIO=4 followed immediately by WebSocket upgrade requests to the same endpoint with a mismatched or missing EIO parameter (e.g., EIO=3 or absent) from the same source IP.
  • Logs: Node.js process logs showing an uncaught exception or unhandled error originating from the Engine.IO heartbeat or parser module; connection_error events with code: 3 (BAD_REQUEST) and context.name: 'PROTOCOL_MISMATCH' in application logs (visible after patching, but the crash may prevent logging in unpatched versions).
  • Process: Sudden, unexpected termination of the Node.js process hosting the Socket.IO/Engine.IO server; process manager (e.g., PM2, systemd) logs showing repeated restarts of the Node.js service.
  • Application: All active Socket.IO client connections dropping simultaneously without a graceful shutdown sequence (Socket.IO Advisory).

Mitigation and workarounds

The vulnerability is fixed in engine.io@6.6.10; users should upgrade immediately. If using Socket.IO packages that depend on Engine.IO, update to a Socket.IO release that bundles the patched Engine.IO version. If immediate upgrading is not possible, two configuration-based workarounds are available: (1) disable transport upgrades entirely with allowUpgrades: false, or (2) restrict to a single transport (e.g., WebSocket only) with transports: ['websocket'] — note both options may affect client compatibility. As an additional proxy/middleware-layer mitigation, reject Engine.IO requests for an existing sid when the EIO parameter is missing or mismatched, though upgrading remains the recommended fix (Socket.IO Advisory, Release Notes).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-102599HIGH7.5
  • JavaScript logoJavaScript
  • engine.io
NoYesSep 29, 2026
GHSA-v53p-9fqp-m79jHIGH7.5
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 29, 2026
GHSA-p634-w6r4-rjp2MEDIUM5.9
  • JavaScript logoJavaScript
  • adm-zip
NoYesSep 29, 2026
GHSA-g57g-f23g-4646MEDIUM5.3
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 29, 2026
GHSA-c6fg-446q-cg94MEDIUM5.3
  • JavaScript logoJavaScript
  • adm-zip
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management