#1144515 python-engineio: CVE-2026-48804

Package:
src:python-engineio
Source:
src:python-engineio
Submitter:
Salvatore Bonaccorso
Date:
2026-08-17 19:23:02 UTC
Severity:
normal
Tags:
#1144515#5
Date:
2026-08-16 12:58:38 UTC
From:
To:
Hi,

The following vulnerability was published for python-engineio.

CVE-2026-48804[0]:
| python-socketio is a Python implementation of the Socket.IO realtime
| client and server. The python-socketio server stores binary `EVENT`
| and `ACK` messages in memory while it waits to receive their binary
| attachments. Once all the attachments are received, these messages
| are then processed. Prior to version 5.16.4, an attacker can submit
| a binary message and intentionally omit sending one or more of its
| attachments to cause the message along with the partial list of
| received attachments to stay in memory for a long time. Version
| 5.16.4 takes the following measures to address this issue: Binary
| packets are only accepted from authenticated clients and, when a
| client disconnects, the server checks if there is a partial binary
| message being held for the client and deletes it.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48804
https://www.cve.org/CVERecord?id=CVE-2026-48804
[1] https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
[2] https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144515#10
Date:
2026-08-17 19:21:21 UTC
From:
To:
Ack.

thanks,

Em 16/08/2026 09:58, Salvatore Bonaccorso escreveu: