THREAT OPS › Threat News › [GHSA] GHSA-gr94-w7qr-f4j3 (high) — Socket.IO: Engine.IO WebTransport SID DoS
[GHSA] GHSA-gr94-w7qr-f4j3 (high) — Socket.IO: Engine.IO WebTransport SID DoS
GHSA-gr94-w7qr-f4j3 Severity: high CVE: CVE-2026-59724
Socket.IO: Engine.IO WebTransport SID DoS
### Impact
Engine.IO servers with **WebTransport enabled** are vulnerable to a remotely triggerable denial of service.
A malicious unauthenticated client can send a crafted WebTransport upgrade request containing a specially chosen session ID, such as `__proto__`. Because the session ID lookup did
Indicators of compromise
- 1fa1f46cd420ac5b57bb4c04c959b58f3c79158csha1
- CVE-2026-59724cve
- https://www.npmjs.com/package/engine.iourl
- socket.iodomain
Original source: https://github.com/advisories/GHSA-gr94-w7qr-f4j3