CVE-2026-48804
### Impact The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. An attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. ### Patches Version 5.16.2 takes the following measures to address this issue: - Binary packets are only accepted from authenticated clients. - When a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.
Properties
- ghsa_id
- GHSA-5w7q-77mv-v69f
- severity
- high
- summary
- python-socketio: Binary attachment accumulation can cause denial of service
- cvss_score
- 7.5
- cve_id
- CVE-2026-48804
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- false
- ghsa_published
- 2026-06-26T20:51:58Z
- source_url
- https://github.com/advisories/GHSA-5w7q-77mv-v69f
- ghsa_updated
- 2026-06-26T20:51:58Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph