Source: python-engineio
Version: 4.13.0-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for python-engineio.

CVE-2026-48804[0]:
| python-socketio is a Python implementation of the Socket.IO realtime
| client and server. The python-socketio server stores binary `EVENT`
| and `ACK` messages in memory while it waits to receive their binary
| attachments. Once all the attachments are received, these messages
| are then processed. Prior to version 5.16.4, an attacker can submit
| a binary message and intentionally omit sending one or more of its
| attachments to cause the message along with the partial list of
| received attachments to stay in memory for a long time. Version
| 5.16.4 takes the following measures to address this issue: Binary
| packets are only accepted from authenticated clients and, when a
| client disconnects, the server checks if there is a partial binary
| message being held for the client and deletes it.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48804
    https://www.cve.org/CVERecord?id=CVE-2026-48804
[1] 
https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
[2] 
https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to