CVE-2026-102600: Unhandled Runtime Exception via Unsafe Prototype Lookup in @socket.io/cluster-engine
Vulnerability ID: CVE-2026-102600
CVSS Score: 7.5
Published: 2026-10-05
A critical Denial of Service (DoS) vulnerability exists in @socket.io/cluster-engine before version 0.1.1. Unauthenticated remote attackers can crash the server process by supplying inherited prototype property names as session identifiers.
TL;DR
Unauthenticated remote attackers can trigger a Node.js process crash and Denial of Service in @socket.io/cluster-engine by passing prototype-inherited properties as session IDs.
Technical Details
- CWE ID: CWE-20
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- EPSS Score: 0.00366 (Percentile: 28.17%)
- Impact: Denial of Service
- Exploit Status: None
- KEV Status: Not listed
Affected Systems
Code Analysis
Commit: 830e364
fix(cluster-engine): guard client lookups against prototype pollution
Mitigation Strategies
- Upgrade @socket.io/cluster-engine to version 0.1.1 or higher.
- Deploy WAF rules to block incoming queries containing prototype pollution payloads on Socket.IO paths.
- Initialize lookup maps using Object.create(null) to prevent dynamic prototype resolving.
Remediation Steps:
- Navigate to the project directory containing the affected package.
- Execute the update command: npm install @socket.io/cluster-engine@0.1.1
- Validate the node_modules structure to ensure older versions are purged.
- Restart the clustered server process to apply the changes.
References
- GitHub Security Advisory GHSA-wfpm-5gcm-94cg
- Official Fix Commit
- Release Tag @socket.io/cluster-engine@0.1.1
- NVD Record
- CVE.org Record
Read the full report for CVE-2026-102600 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)