CVE-2020-36048: Socket Engine.io

High severity, CVSS 7.5. EPSS: 3.3% chance of exploitation in the next 30 days.

Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.

Affected products

  • Socket Engine.io: before 4.0.0 (fixed in 4.0.0)

Published 2021-01-08. Last modified 2026-06-17.