← العودة للجدول
CVE-2026-59724
CVE-2026-59724 — Socket.IO: Engine.IO WebTransport SID DoS
📅 2026-09-01
🟠 High 🔥 No GHSA Exploit Open Source CVSS 7.5

📋 الوصف الكامل

### Impact Engine.IO servers with **WebTransport enabled** are vulnerable to a remotely triggerable denial of service. A malicious unauthenticated client can send a crafted WebTransport upgrade request containing a specially chosen session ID, such as `__proto__`. Because the session ID lookup did not properly verify that the key was an own property of the clients object, the lookup could resolv

💻 الأنظمة المتأثرة

Node.js

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-59724

📡 المصدر

GHSA

✅ الحلول والتخفيف

Update to v6.5.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←