Sceawere
Vulnerability Detail
CVE-2026-102600UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Prototype Pollution Denial of Service
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 9h ago
- Vendor
- socketio
- Product
- socket.io
- Attack Type
- CWE-20: Improper Input Validation
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Node.js process to crash and resulting in denial of service. Applications that do not use @socket.io/cluster-engine are not affected. This issue is fixed in version 0.1.1.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-29T16:17:06.180Z",
"pubdate": "2026-09-29T16:17:06.180Z",
"executiveSummary": "A Prototype Pollution vulnerability exists in @socket.io/cluster-engine prior to version 0.1.1, facilitating a Denial of Service (DoS) attack.\nThe flaw originates from the unsafe lookup of session IDs within the cluster-engine component, where attacker-controlled input is used to resolve properties on objects without sufficient validation.\nBy submitting specially crafted session IDs containing property names like __proto__ or constructor, an attacker can traverse the JavaScript object prototype chain.\nThis manipulation interferes with internal object state, ultimately triggering a Node.js process crash.\nThe vulnerability is restricted to applications specifically utilizing @socket.io/cluster-engine in clustered environments.\nSuccessful exploitation results in an immediate service disruption, impacting availability for all connected clients on the targeted node.",
"technicalDetails": "The vulnerability is a classic Prototype Pollution flaw located within the session management logic of @socket.io/cluster-engine.\nIn clustered Node.js environments, @socket.io/cluster-engine maintains a mapping of session IDs to connected client instances. The implementation improperly validates session IDs provided by external entities before using them as keys in a lookup object.\nJavaScript objects inherit properties from the Object.prototype. If an application performs a lookup using an attacker-supplied key without verifying that the key is a direct property of the object, the engine may resolve properties from the prototype chain.\nAn attacker can craft a payload containing reserved property names, such as '__proto__', 'constructor', or 'prototype'. When the application attempts to access or assign data based on these keys, the JavaScript engine traverses up the prototype chain.\nThis allows the attacker to reach the base Object.prototype and manipulate it. In the context of @socket.io/cluster-engine, injecting these malicious keys disrupts the internal state mapping used for session management.\nThe attack flow proceeds as follows: 1) The attacker initiates communication with the clustered Socket.IO service. 2) The attacker sends a request containing a session ID designed to trigger prototype resolution (e.g., '__proto__'). 3) The backend logic uses this string as an object key during session retrieval or storage operations. 4) The lookup resolves to a prototype property rather than an actual session object. 5) The discrepancy between expected data types and the prototype-injected values results in an unhandled exception or an invalid state transition. 6) The Node.js process, unable to recover from the corruption, crashes to prevent further undefined behavior, resulting in a Denial of Service.\nThis issue affects all versions of @socket.io/cluster-engine prior to 0.1.1. No authentication is required to initiate the malicious request, and the attack can be executed remotely over the network. The primary impact is the loss of availability for the specific cluster node processing the request."
}