CVE-2026-33151
Impact
A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.
Patches
| Version range | Used by | Fixed version |
|------------------|--------------------------------------------|---------------|
| >=4.0.0 <4.2.6 | socket.io@4.x and socket.io-client@4.x | 4.2.6 |
| >=3.4.0 <3.4.4 | socket.io@2.x | 3.4.4 |
| <3.3.5 | socket.io-client@2.x | 3.3.5 |
Workarounds
There is no known workaround except upgrading to a safe version.
For more information
If you have any questions or comments about this advisory:
- Open a discussion here
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/socketio/socket.io/security/advisories/GHSA-677m-j7p3-52f9, https://nvd.nist.gov/vuln/detail/CVE-2026-33151, https://github.com/socketio/socket.io/commit/719f9ebab0772ffb882bd614b387e585c1aa75d4, https://github.com/socketio/socket.io/commit/9d39f1f080510f036782f2177fac701cc041faaf, https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78, https://github.com/socketio/socket.io
