Description
python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the way the python-socketio server processes binary messages. When a binary EVENT or ACK packet is received, the server holds it in memory until all its attachments are delivered. Prior to version 5.16.4 an attacker can send a binary packet and then fail to send one or more of its required attachments, causing the incomplete message to remain in memory indefinitely. As the message stays resident, the process consumes more and more memory, potentially exhausting available resources and resulting in a denial of service. This is a resource exhaustion weakness identified as CWE‑770.

Affected Systems

All installations of miguelgrinberg:python-socketio version 5.16.3 and earlier are affected. The issue was fixed in release 5.16.4, which validates that binary packets come only from authenticated clients and deletes any partial message when a client disconnects.

Risk and Exploitability

The reported CVSS score is 7.5, which places the vulnerability in the high severity range. The EPSS score is below 1%, indicating that exploitation attempts are currently expected to be rare, and it is not listed in the CISA KEV catalog. The attack would be carried out via the network, requiring an existing client connection to the server that can send binary packets. Because the flaw is triggered by crafting a message with missing attachments, the exploitation path is straightforward for an attacker who can inject packets, but the overall probability of finding an exploitable target remains low. Still, the potential impact on service availability warrants timely remediation.

Generated by OpenCVE AI on August 12, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the python-socketio package to version 5.16.4 or later.
  • Enable authentication for all Socket.IO connections, ensuring that only verified clients can send binary packets.
  • Implement monitoring of memory usage for Socket.IO server processes and enforce limits or automatic restarts if memory thresholds are exceeded.

Generated by OpenCVE AI on August 12, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5w7q-77mv-v69f python-socketio: Binary attachment accumulation can cause denial of service
History

Sat, 15 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Miguelgrinberg
Miguelgrinberg python-socketio
Vendors & Products Miguelgrinberg
Miguelgrinberg python-socketio

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.
Title python-socketio: Binary attachment accumulation can cause denial of service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Miguelgrinberg Python-socketio
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T14:39:14.373Z

Reserved: 2026-05-22T20:57:10.975Z

Link: CVE-2026-48804

cve-icon Vulnrichment

Updated: 2026-08-13T14:39:10.596Z

cve-icon NVD

Status : Received

Published: 2026-08-11T20:17:42.580

Modified: 2026-08-13T15:19:41.157

Link: CVE-2026-48804

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T19:17:53Z

Links: CVE-2026-48804 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:33Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling