CVE-2026-102600
Published 29 September 2026 · tracked since 30 September 2026
Description
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve t
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-72897 HIGH 7.5
- CVE-2026-54873
- CVE-2026-54875 LOW 3.7
- CVE-2026-19743 HIGH 7.8
- CVE-2026-35189
- CVE-2026-35191
- CVE-2026-42772
- CVE-2026-102598
- CVE-2026-102601 LOW 3.5
- CVE-2026-102630 MEDIUM 4.7