Disclosure summary
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1.
Source-reported weakness categories
CWE-20, CWE-1321
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-wfpm-5gcm-94cg
Open original source · Updated Oct 05, 2026
Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @socket.io/cluster-engine | < 0.1.1 | 0.1.1 |
NIST National Vulnerability Database · NVD-CVE-2026-102600
Open original source · Updated Sep 30, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-09-29T12:17:06-04:00
MODIFIED 2026-09-30T15:38:27-04:00
INGESTED 2026-10-06T11:43:05-04:00