Uncaught Exception Affecting engine.io package, versions >=6.6.0 <6.6.10


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Uncaught Exception vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-ENGINEIO-20335255
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditThai Son Dinh

Introduced: 29 Sep 2026

NewCVE-2026-102599  (opens in a new tab)
CWE-248  (opens in a new tab)

How to fix?

Upgrade engine.io to version 6.6.10 or higher.

Overview

engine.io is a realtime engine behind Socket.IO. It provides the foundation of a bidirectional connection between client and server

Affected versions of this package are vulnerable to Uncaught Exception via the session upgrade handler in server.ts, where follow-up requests and transport upgrades do not validate that the Engine.IO protocol revision matches the one negotiated during the initial handshake. An attacker can send an upgrade request with a mismatched or missing EIO query parameter, causing a transport using a different parser and heartbeat mode to attach to an existing session, which disrupts the session and results in a crash.

CVSS Base Scores

version 4.0
version 3.1