highCVSS 7.5Vulnerability

CVE-2026-48804

### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. ### Patches Version 5.16.2 takes the following measures to address this issue: - Binary packets are only accepted from authenticated clients. - When a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.

Properties

ghsa_id
GHSA-5w7q-77mv-v69f
severity
high
summary
python-socketio: Binary attachment accumulation can cause denial of service
cvss_score
7.5
cve_id
CVE-2026-48804
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
false
ghsa_published
2026-06-26T20:51:58Z
source_url
https://github.com/advisories/GHSA-5w7q-77mv-v69f
ghsa_updated
2026-06-26T20:51:58Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/python-socketio

AFFECTS (1)

[Software]pip/python-socketio

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-48804 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal