CVE-2026-59724: Socket Engine.io
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session ID such as __proto__ through an inherited property of the clients object during WebTransport upgrade handling, causing a TypeError and denial of service. This issue is fixed in version 6.6.7.
Affected products
- Socket Engine.io: from 6.5.0, before 6.6.7 (fixed in 6.6.7)
Published 2026-07-08. Last modified 2026-07-13.