THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gr94-w7qr-f4j3 (high) — Socket.IO: Engine.IO WebTransport SID DoS

[GHSA] GHSA-gr94-w7qr-f4j3 (high) — Socket.IO: Engine.IO WebTransport SID DoS

highgithub_advisoriesPublished 2026-08-31

GHSA-gr94-w7qr-f4j3 Severity: high CVE: CVE-2026-59724

Socket.IO: Engine.IO WebTransport SID DoS

### Impact

Engine.IO servers with **WebTransport enabled** are vulnerable to a remotely triggerable denial of service.

A malicious unauthenticated client can send a crafted WebTransport upgrade request containing a specially chosen session ID, such as `__proto__`. Because the session ID lookup did

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gr94-w7qr-f4j3