{"id":"GHSA-j4f2-536g-r55m","summary":"Resource exhaustion in engine.io","details":"Engine.IO before 4.0.0 and 3.6.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.","aliases":["CVE-2020-36048"],"modified":"2025-05-29T23:06:32Z","published":"2022-02-09T22:29:04Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-06T22:58:33Z","nvd_published_at":"2021-01-08T00:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-36048"},{"type":"WEB","url":"https://github.com/socketio/engine.io/commit/58e274c437e9cbcf69fd913c813aad8fbd253703"},{"type":"WEB","url":"https://github.com/socketio/engine.io/commit/734f9d1268840722c41219e69eb58318e0b2ac6b"},{"type":"WEB","url":"https://blog.caller.xyz/socketio-engineio-dos"},{"type":"WEB","url":"https://github.com/bcaller/kill-engine-io"},{"type":"PACKAGE","url":"https://github.com/socketio/engine.io"}],"affected":[{"package":{"name":"engine.io","ecosystem":"npm","purl":"pkg:npm/engine.io"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-j4f2-536g-r55m/GHSA-j4f2-536g-r55m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}