Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38355

21
FAUCET Score

CVE-2024-38355 is a denial-of-service vulnerability affecting Socket.IO, an open-source real-time communication framework, where a specially crafted packet can crash the Node.js server process. Rated 7.3 HIGH, this vulnerability has a network attack vector, low attack complexity, and can lead to low impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, Siemens has issued an advisory regarding its impact on their industrial products, indicating some industry awareness. The issue is resolved in Socket.IO versions 4.6.2 and later, and a backport is available for the 2.x branch.

Impacted Technologies

VendorProductVersion(s)CPE
SocketioSocket.Io
< 2.5.1, >= 3.0.0,< 4.6.2CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.69%
Probability of exploitation in next 30 days
EPSS Percentile
49.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0069 is in the 25th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

npmpatch availablevia ghsa
Product: socket.ioFixed in: 2.5.1
npmpatch availablevia ghsa
Product: socket.ioFixed in: 4.6.2
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: socket.io
redhatend of lifevia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: socket.io

Vendor Advisories (2)

redhatCVE-2024-38355Important

socket.io: Unhandled 'error' event

Jun 20, 2024
npmGHSA-25hc-qcg6-38wjmedium

socket.io has an unhandled 'error' event

Jun 19, 2024

References

vicarius.io / vsociety/posts/unhandled-exception-in-socketio-cve-2024-38355
github.com / socketio/socket.io/commit/15af22fc22bc6030fcead322c106f07640336115
github.com / socketio/socket.io/commit/d30630ba10562bf987f4d2b42440fc41a828119c
github.com / socketio/socket.io/security/advisories/GHSA-25hc-qcg6-38wj