
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-102599 is a denial-of-service vulnerability in the Engine.IO / Socket.IO npm package, named "Engine.IO Protocol Revision Mismatch DoS." It affects engine.io versions >= 6.6.0 and < 6.6.10, and was first published by maintainer darrachequesne on September 14, 2026, with the advisory added to the GitHub Advisory Database on September 29, 2026. The vulnerability allows an unauthenticated remote attacker to crash the Node.js server process by exploiting a protocol revision mismatch during WebSocket transport upgrades. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Socket.IO Advisory).
The root cause is an uncaught exception (CWE-248) triggered by a missing validation step: the server failed to verify that the EIO query parameter in a WebSocket upgrade request matched the protocol revision negotiated during the initial session handshake. Each transport independently computed its protocol revision from the request's query parameters, while the session stored its own pinned revision. An attacker could establish a legitimate Engine.IO v4 session (via polling with EIO=4) and then send a WebSocket upgrade request with a mismatched or omitted EIO parameter — an omitted parameter defaults to protocol v3 on the upgrade path — causing the server to attach a transport with an incompatible parser and heartbeat mode. Under these conditions, a crafted heartbeat packet triggers an uncaught exception that terminates the Node.js process. The fix, applied in commit 86db1fc, introduces a computeProtocolRevision() helper and rejects upgrade requests where the derived protocol does not match the session's pinned protocol (Socket.IO Advisory, Fix Commit).
Successful exploitation results in a complete denial of service through an unhandled Node.js process crash, making the server unavailable to all connected clients. There is no confidentiality or integrity impact — the vulnerability is purely an availability issue. Because a single unauthenticated request sequence can crash the entire Node.js process, all Socket.IO/Engine.IO sessions on the affected server are terminated simultaneously, and the service remains unavailable until the process is restarted (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the advisory publication date. The vulnerability requires no privileges and no user interaction, and is reachable over the network with low attack complexity, making it straightforward to exploit by any network-accessible attacker against a vulnerable server. The CVE status is listed as "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. The reporter credited is sondt99 (GitHub Advisory, Socket.IO Advisory).
engine.io >= 6.6.0 and < 6.6.10 that permits transport upgrades (the default configuration).EIO=4 to initiate a handshake and obtain a valid session ID (sid): GET /engine.io/?transport=polling&EIO=4sid, send a WebSocket upgrade request with a mismatched or omitted EIO parameter (e.g., EIO=3 or no EIO at all): ws://target/engine.io/?transport=websocket&sid=<SID> (omitting EIO or setting EIO=3)/engine.io/?transport=polling&EIO=4 followed immediately by WebSocket upgrade requests to the same endpoint with a mismatched or missing EIO parameter (e.g., EIO=3 or absent) from the same source IP.connection_error events with code: 3 (BAD_REQUEST) and context.name: 'PROTOCOL_MISMATCH' in application logs (visible after patching, but the crash may prevent logging in unpatched versions).The vulnerability is fixed in engine.io@6.6.10; users should upgrade immediately. If using Socket.IO packages that depend on Engine.IO, update to a Socket.IO release that bundles the patched Engine.IO version. If immediate upgrading is not possible, two configuration-based workarounds are available: (1) disable transport upgrades entirely with allowUpgrades: false, or (2) restrict to a single transport (e.g., WebSocket only) with transports: ['websocket'] — note both options may affect client compatibility. As an additional proxy/middleware-layer mitigation, reject Engine.IO requests for an existing sid when the EIO parameter is missing or mismatched, though upgrading remains the recommended fix (Socket.IO Advisory, Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."