GHSA-wfpm-5gcm-94cg: Input Validation

Published Oct 5, 2026
·
Updated

Impact

This is a prototype pollution / improper client lookup vulnerability in @socket.io/cluster-engine.

Servers using @socket.io/cluster-engine may be impacted when attacker-controlled session IDs are processed in clustered deployments. A malicious client could use special property names such as proto, constructor, or other inherited object keys as a session identifier, causing the server to read properties from the object prototype chain instead of only real connected clients.

The impact is denial of service through process crash.

Applications not using @socket.io/cluster-engine are not affected by this specific issue.

Affected versions:

@socket.io/cluster-engine@0.1.0

Patches

The issue was fixed in:

@socket.io/cluster-engine@0.1.1

Workarounds

If upgrading immediately is not possible, users can reduce exposure by:

- Rejecting or sanitizing suspicious session IDs before they reach the cluster engine. - Running the cluster engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests.

These workarounds are defense-in-depth only. Upgrading to a patched version is recommended.

Affected Software

1 affected componentFixes available
npm/@socket.io/cluster-engine<0.1.1
0.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@socket.io/cluster-engine to a version that resolves this vulnerability.

    Fixed in 0.1.1
  2. Compensating control

    Reject or sanitize suspicious session IDs, including special property names such as __proto__ and constructor, before they reach @socket.io/cluster-engine.

  3. Compensating control

    Run @socket.io/cluster-engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:44 PM
Data Sourced
via GitHub·11:44 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Only servers using @socket.io/cluster-engine in clustered deployments are affected by this issue. Applications that do not use @socket.io/cluster-engine are not affected by this specific vulnerability.

2

What does an attacker need to trigger the issue?

An attacker needs to be able to have attacker-controlled session IDs processed by the cluster engine. Special identifiers such as __proto__, constructor, or other inherited object-property names can cause improper client lookup and crash the process.

3

Which version should be upgraded?

Version 0.1.0 is affected. The issue is fixed in @socket.io/cluster-engine 0.1.1.

4

What can be done before upgrading?

Reject or sanitize suspicious session IDs before they reach the cluster engine, and place the cluster engine behind trusted infrastructure that prevents arbitrary clients from crafting raw Engine.IO session-related requests. These measures are defense-in-depth; upgrading is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203