Socket develops a suite of widely used real-time communication libraries—particularly Socket.IO and Engine.IO—that enable bidirectional event-driven messaging in web applications across millions of deployed instances. The vendor's vulnerability profile centers on input-validation and resource-handling weaknesses endemic to protocol parsers and event-dispatching systems, with a moderate tendency toward serious severity outcomes. Defenders should monitor Socket's advisories closely given the ubiquity of these libraries in production web stacks; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Socket over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59725HIGH Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-59724HIGH Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO servers with WebTransport enabled can resolve a crafted session | Jul 8, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-2421CRITICAL Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to | Oct 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-36048HIGH Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport. | Jan 8, 2021 | 7.5 | 26 | NO | NO |
CVE-2026-33151HIGH Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3.4.4, and 4.2.6, a specially crafted Socket.IO packet can mak | Mar 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2022-21676HIGH Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an unca | Jan 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25867HIGH The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format. | Aug 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-36049HIGH socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used. | Jan 8, 2021 | 7.5 | 24 | NO | NO |
CVE-2017-16031HIGH Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the I | Jun 4, 2018 | 7.5 | 24 | NO | NO |
CVE-2023-32695HIGH socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaug | May 27, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Socket.
Media articles that mention a CVE ID that affects a product developed by Socket — matched by CVE ID, not by vendor name.