THREAT OPS › Threat News › [NVD] CVE-2026-48809 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att
[NVD] CVE-2026-48809 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att
CVE-2026-48809 CVSS: 7.5 HIGH Published: 2026-08-11T19:17:37.267
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary
Indicators of compromise
- CVE-2026-48809cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48809