← Vulnerability feed

Vulnerability record · CVE-2022-21676 · published 12 January 2022

CVE-2022-21676: Socket engine.io vulnerability

Socket · Engine.Io

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the `engine.io` package starting from version `4.0.0`, including those who uses depending packages like `socket.io`. Versions prior to `4.0.0` are not impacted. A fix has been released for each major branch, namely `4.1.2` for the `4.x.x` branch, `5.2.1` for the `5.x.x` branch, and `6.1.1` for the `6.x.x` branch. There is no known workaround except upgrading to a safe version.

7.5 CVSS 3.1 High EPSS 2.8% · top 14.3% CWE-754 · CWE-754CWE-755 · CWE-755
7.5CVSS 3.1 base score, v2 5.0
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the `engine.io` package starting from version `4.0.0`, including those who uses depending packages like `socket.io`. Versions prior to `4.0.0` are not impacted. A fix has been released for each major branch, namely `4.1.2` for the `4.x.x` branch, `5.2.1` for the `5.x.x` branch, and `6.1.1` for the `6.x.x` branch. There is no known workaround except upgrading to a safe version.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/socketio/engine.io/commit/66f889fc1d966bf5bfa0de1939069153643874ab PatchThird Party Advisory
https://github.com/socketio/engine.io/commit/a70800d7e96da32f6e6622804ef659ebc58659db PatchThird Party Advisory
https://github.com/socketio/engine.io/commit/c0e194d44933bd83bf9a4b126fca68ba7bf5098c PatchThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/4.1.2 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/5.2.1 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/6.1.1 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/security/advisories/GHSA-273r-mgr4-v34f Third Party Advisory
https://security.netapp.com/advisory/ntap-20220209-0002/ Third Party Advisory
https://github.com/socketio/engine.io/commit/66f889fc1d966bf5bfa0de1939069153643874ab PatchThird Party Advisory
https://github.com/socketio/engine.io/commit/a70800d7e96da32f6e6622804ef659ebc58659db PatchThird Party Advisory
https://github.com/socketio/engine.io/commit/c0e194d44933bd83bf9a4b126fca68ba7bf5098c PatchThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/4.1.2 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/5.2.1 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/releases/tag/6.1.1 Release NotesThird Party Advisory
https://github.com/socketio/engine.io/security/advisories/GHSA-273r-mgr4-v34f Third Party Advisory
https://security.netapp.com/advisory/ntap-20220209-0002/ Third Party Advisory

Track CVE-2022-21676 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-59725Socket engine.io improper resource shutdown vulnerabilitySocket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport do…EPSS 0.64%7.5CVE-2026-59724Socket engine.io improper input validation vulnerabilitySocket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enable…EPSS 0.61%7.5CVE-2020-36048Socket engine.io uncontrolled resource consumption vulnerabilityEngine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.EPSS 3.2%6.5CVE-2023-31125Socket engine.io vulnerabilityEngine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception…EPSS 1.3%6.5CVE-2022-41940Socket engine.io vulnerabilityEngine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted H…EPSS 2.1%9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed8.7CVE-2024-3393PAN-OS DNS Security packet causes firewall reboot and maintenance modeA denial of service flaw in the DNS Security feature of Palo Alto Networks PAN-OS lets an unauthenticated attacker send a crafted packet through the …KEVEPSS 28%analysed8.8CVE-2023-41993Apple WebKit improper check allows arbitrary code executionCVE-2023-41993 is a WebKit flaw where processing web content can lead to arbitrary code execution, addressed with improved checks. Apple states it is…KEVEPSS 24%analysed

Source: NIST National Vulnerability Database (record CVE-2022-21676), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.