Sceawere

Vulnerability Detail

CVE-2026-102600UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Prototype Pollution Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
9h ago
Vendor
socketio
Product
socket.io
Attack Type
CWE-20: Improper Input Validation
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T16:17:06.180Z",
  "pubdate": "2026-09-29T16:17:06.180Z",
  "executiveSummary": "A Prototype Pollution vulnerability exists in @socket.io/cluster-engine prior to version 0.1.1, facilitating a Denial of Service (DoS) attack.\nThe flaw originates from the unsafe lookup of session IDs within the cluster-engine component, where attacker-controlled input is used to resolve properties on objects without sufficient validation.\nBy submitting specially crafted session IDs containing property names like __proto__ or constructor, an attacker can traverse the JavaScript object prototype chain.\nThis manipulation interferes with internal object state, ultimately triggering a Node.js process crash.\nThe vulnerability is restricted to applications specifically utilizing @socket.io/cluster-engine in clustered environments.\nSuccessful exploitation results in an immediate service disruption, impacting availability for all connected clients on the targeted node.",
  "technicalDetails": "The vulnerability is a classic Prototype Pollution flaw located within the session management logic of @socket.io/cluster-engine.\nIn clustered Node.js environments, @socket.io/cluster-engine maintains a mapping of session IDs to connected client instances. The implementation improperly validates session IDs provided by external entities before using them as keys in a lookup object.\nJavaScript objects inherit properties from the Object.prototype. If an application performs a lookup using an attacker-supplied key without verifying that the key is a direct property of the object, the engine may resolve properties from the prototype chain.\nAn attacker can craft a payload containing reserved property names, such as '__proto__', 'constructor', or 'prototype'. When the application attempts to access or assign data based on these keys, the JavaScript engine traverses up the prototype chain.\nThis allows the attacker to reach the base Object.prototype and manipulate it. In the context of @socket.io/cluster-engine, injecting these malicious keys disrupts the internal state mapping used for session management.\nThe attack flow proceeds as follows: 1) The attacker initiates communication with the clustered Socket.IO service. 2) The attacker sends a request containing a session ID designed to trigger prototype resolution (e.g., '__proto__'). 3) The backend logic uses this string as an object key during session retrieval or storage operations. 4) The lookup resolves to a prototype property rather than an actual session object. 5) The discrepancy between expected data types and the prototype-injected values results in an unhandled exception or an invalid state transition. 6) The Node.js process, unable to recover from the corruption, crashes to prevent further undefined behavior, resulting in a Denial of Service.\nThis issue affects all versions of @socket.io/cluster-engine prior to 0.1.1. No authentication is required to initiate the malicious request, and the attack can be executed remotely over the network. The primary impact is the loss of availability for the specific cluster node processing the request."
}
CVE-2026-102600: Prototype Pollution Denial of Service (HIGH Severity, CVSS: 7.5) | Sceawere