๐Ÿ” CVE Alert

CVE-2026-48804

HIGH 7.5

python-socketio: Binary attachment accumulation can cause denial of service

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.

CWE CWE-770
Vendor miguelgrinberg
Product python-socketio
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for miguelgrinberg python-socketio

Be the first to know when new high vulnerabilities affecting miguelgrinberg python-socketio are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

miguelgrinberg / python-socketio
< 5.16.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f github.com: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e