Description
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. This issue primarily affects synchronous servers. Asynchronous servers allocate background tasks instead of physical threads, which are lightweight and less likely to cause denial of service. However, the fix that was implemented was also applied to the asynchronous case. Version 4.13.2 addresses this issue as follows: The initial background thread (or async task( for heartbeat management is only launched if a client passes authentication in the `connect` handler; and the server now ensures that there is only one background heatbeat thread (or async task) per client at a given point in time. Out of sequence PONG packets are now discarded when an active heartbeat thread is already running.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows an attacker to spawn an uncontrolled number of background threads on the python-engineio server. Unbounded thread creation can exhaust system resources, leading to degraded performance or a complete denial of service. The weakness is a classic resource exhaustion problem, captured by CWE‑770, and affects the availability of the application.

Affected Systems

The vulnerability is present in python-engineio versions prior to 4.13.2, distributed by miguelgrinberg. Only the synchronous server model is directly impacted, although the same logic applies to asynchronous servers after the applied fix.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity issue, but the EPSS score of less than 1% indicates that exploitation is unlikely at this time. Since the vulnerability is triggered by establishing connections and receiving PONG packets, the attack vector is remote and can be achieved without special privileges. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at present.

Generated by OpenCVE AI on August 12, 2026 at 20:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade python-engineio to version 4.13.2 or later.
  • Run the server in async mode to replace physical threads with lightweight tasks, mitigating the thread abuse risk.
  • If you cannot upgrade immediately, limit the number of concurrent connections or employ rate limiting to constrain thread churn.
  • As a temporary guard, modify the server configuration to require authentication before launching heartbeat threads, reducing the window for exploitation.

Generated by OpenCVE AI on August 12, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cgwc-pv48-fhj5 python-engineio has unbound thread allocation that can cause denial of service
History

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Miguelgrinberg
Miguelgrinberg python-engineio
Vendors & Products Miguelgrinberg
Miguelgrinberg python-engineio

Tue, 11 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet. This issue primarily affects synchronous servers. Asynchronous servers allocate background tasks instead of physical threads, which are lightweight and less likely to cause denial of service. However, the fix that was implemented was also applied to the asynchronous case. Version 4.13.2 addresses this issue as follows: The initial background thread (or async task( for heartbeat management is only launched if a client passes authentication in the `connect` handler; and the server now ensures that there is only one background heatbeat thread (or async task) per client at a given point in time. Out of sequence PONG packets are now discarded when an active heartbeat thread is already running.
Title python-engineio has unbound thread allocation that can cause denial of service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Miguelgrinberg Python-engineio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T14:35:20.691Z

Reserved: 2026-05-22T20:57:10.975Z

Link: CVE-2026-48802

cve-icon Vulnrichment

Updated: 2026-08-13T14:34:30.908Z

cve-icon NVD

Status : Received

Published: 2026-08-11T19:17:37.120

Modified: 2026-08-13T15:19:41.033

Link: CVE-2026-48802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:40Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling