Known Vulnerabilities for Engine.io-client by Socket
Listed below are 1 of the newest known vulnerabilities associated with "Engine.io-client" by "Socket".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104058 json | Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-103540 json | A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function C... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-102600 json | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine u... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-101903 json | Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression a... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-100705 json | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.16... | Not Provided | 2026-09-26 | 2026-09-26 |
| CVE-2026-93042 json | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors without ca... | Not Provided | 2026-09-17 | 2026-09-18 |
| CVE-2026-91921 json | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1mil... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-82062 json | A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled featur... | Not Provided | 2026-09-08 | 2026-09-08 |
| CVE-2026-78204 json | Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessContr... | Not Provided | 2026-08-24 | 2026-08-24 |
| CVE-2026-77239 json | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes auth... | Not Provided | 2026-09-18 | 2026-09-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Socket | Engine.io-client | 3.4.0 | |||
| Application | Socket | Engine.io-client | 3.3.2 | |||
| Application | Socket | Engine.io-client | 3.3.1 | |||
| Application | Socket | Engine.io-client | 3.3.0 | |||
| Application | Socket | Engine.io-client | 3.2.1 | |||
| Application | Socket | Engine.io-client | 3.2.0 | |||
| Application | Socket | Engine.io-client | 3.1.6 | |||
| Application | Socket | Engine.io-client | 3.1.5 | |||
| Application | Socket | Engine.io-client | 3.1.4 | |||
| Application | Socket | Engine.io-client | 3.1.3 | |||
| Application | Socket | Engine.io-client | 3.1.2 | |||
| Application | Socket | Engine.io-client | 3.1.1 | |||
| Application | Socket | Engine.io-client | 3.1.0 | |||
| Application | Socket | Engine.io-client | 3.0.0 | |||
| Application | Socket | Engine.io-client | 2.1.1 | |||
| Application | Socket | Engine.io-client | 2.1.0 | |||
| Application | Socket | Engine.io-client | 2.0.2 | |||
| Application | Socket | Engine.io-client | 2.0.1 | |||
| Application | Socket | Engine.io-client | 2.0.0 | |||
| Application | Socket | Engine.io-client | 1.8.5 |