Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Socket

First CVE: May 31, 2018Active for: 8 yearsTotal CVEs: 14
35.8
VTI Score
Medium

Socket develops a suite of widely used real-time communication libraries—particularly Socket.IO and Engine.IO—that enable bidirectional event-driven messaging in web applications across millions of deployed instances. The vendor's vulnerability profile centers on input-validation and resource-handling weaknesses endemic to protocol parsers and event-dispatching systems, with a moderate tendency toward serious severity outcomes. Defenders should monitor Socket's advisories closely given the ubiquity of these libraries in production web stacks; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Socket over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2018
8 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59725HIGH
Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP
Jul 8, 20267.533NONO
CVE-2026-59724HIGH
Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session
Jul 8, 20267.533NONO
CVE-2022-2421CRITICAL
Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to
Oct 26, 20229.831NONO
CVE-2020-36048HIGH
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Jan 8, 20217.526NONO
CVE-2026-33151HIGH
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can mak
Mar 20, 20267.525NONO
CVE-2022-21676HIGH
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an unca
Jan 12, 20227.525NONO
CVE-2022-25867HIGH
The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.
Aug 2, 20227.524NONO
CVE-2020-36049HIGH
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
Jan 8, 20217.524NONO
CVE-2017-16031HIGH
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the I
Jun 4, 20187.524NONO
CVE-2023-32695HIGH
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaug
May 27, 20237.523NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
64%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (21.4%)
High0 (0.0%)
None11 (78.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Socket.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Socket — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Socket's Products

View all 5 CNAs →

Top CWEs