CVE-2026-102600
Received Received - Intake

Prototype Pollution in Socket.IO Cluster Engine

Vulnerability report for CVE-2026-102600, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
socket.io cluster-engine to 0.1.1 (inc)
socket.io cluster-engine to 0.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102600 is a prototype pollution vulnerability in the @socket.io/cluster-engine npm package affecting versions prior to 0.1.1. Attackers can manipulate object prototypes using special property names like __proto__ or constructor when processing session IDs in clustered deployments. This causes the Node.js process to crash, leading to denial of service.

Detection Guidance

To detect this vulnerability, check if your system is running a version of @socket.io/cluster-engine prior to 0.1.1. Use commands like 'npm list @socket.io/cluster-engine' or 'npm audit' to identify affected versions. Monitor for unexpected crashes in Node.js processes handling Socket.IO connections.

Impact Analysis

The vulnerability allows remote attackers to crash Node.js processes by sending malicious session IDs, causing denial of service. It requires no privileges or user interaction and can be exploited over a network. Only applications using @socket.io/cluster-engine are affected.

Mitigation Strategies

Upgrade @socket.io/cluster-engine to version 0.1.1 or later immediately. If upgrading is not possible, implement input sanitization for session IDs or restrict access to trusted infrastructure. Review logs for suspicious activity involving __proto__ or constructor properties.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart