DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102600: CVE-2026-102600: Unhandled Runtime Exception via Unsafe Prototype Lookup in @socket.io/cluster-engine

CVE-2026-102600: Unhandled Runtime Exception via Unsafe Prototype Lookup in @socket.io/cluster-engine

Vulnerability ID: CVE-2026-102600
CVSS Score: 7.5
Published: 2026-10-05

A critical Denial of Service (DoS) vulnerability exists in @socket.io/cluster-engine before version 0.1.1. Unauthenticated remote attackers can crash the server process by supplying inherited prototype property names as session identifiers.

TL;DR

Unauthenticated remote attackers can trigger a Node.js process crash and Denial of Service in @socket.io/cluster-engine by passing prototype-inherited properties as session IDs.


Technical Details

  • CWE ID: CWE-20
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.00366 (Percentile: 28.17%)
  • Impact: Denial of Service
  • Exploit Status: None
  • KEV Status: Not listed

Affected Systems

  • @socket.io/cluster-engine
  • @socket.io/cluster-engine: < 0.1.1 (Fixed in: 0.1.1)

Code Analysis

Commit: 830e364

fix(cluster-engine): guard client lookups against prototype pollution

Mitigation Strategies

  • Upgrade @socket.io/cluster-engine to version 0.1.1 or higher.
  • Deploy WAF rules to block incoming queries containing prototype pollution payloads on Socket.IO paths.
  • Initialize lookup maps using Object.create(null) to prevent dynamic prototype resolving.

Remediation Steps:

  1. Navigate to the project directory containing the affected package.
  2. Execute the update command: npm install @socket.io/cluster-engine@0.1.1
  3. Validate the node_modules structure to ensure older versions are purged.
  4. Restart the clustered server process to apply the changes.

References


Read the full report for CVE-2026-102600 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)