THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-48809 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att

[NVD] CVE-2026-48809 (HIGH 7.5) — python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An att

lownvdPublished 2026-08-11

CVE-2026-48809 CVSS: 7.5 HIGH Published: 2026-08-11T19:17:37.267

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-48809