CVE-2020-36048: High severity socket engine.io vulnerability
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
Other sources
Engine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-36048?
CVE-2020-36048 is a vulnerability in Engine.IO before 4.0.0 that allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
How does CVE-2020-36048 affect Socket Engine.io?
CVE-2020-36048 affects Socket Engine.io versions up to but excluding 4.0.0.
What is the severity of CVE-2020-36048?
CVE-2020-36048 has a severity rating of 7.5 (high).
Are there any references or sources related to CVE-2020-36048?
Yes, you can find more information about CVE-2020-36048 at the following sources: [reference 1](https://blog.caller.xyz/socketio-engineio-dos/), [reference 2](https://github.com/bcaller/kill-engine-io), [reference 3](https://github.com/socketio/engine.io/commit/734f9d1268840722c41219e69eb58318e0b2ac6b).
How do I fix CVE-2020-36048?
To fix CVE-2020-36048, you should update Socket Engine.io to version 4.0.0 or later, which includes the necessary patches to address the vulnerability.