#1144515 python-engineio: CVE-2026-48804

Package:
src:python-engineio
Source:
src:python-engineio
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 19:03:03 UTC
Severity:
normal
Tags:
#1144515#5
Date:
2026-08-16 12:58:38 UTC
From:
To:
Hi,

The following vulnerability was published for python-engineio.

CVE-2026-48804[0]:
| python-socketio is a Python implementation of the Socket.IO realtime
| client and server. The python-socketio server stores binary `EVENT`
| and `ACK` messages in memory while it waits to receive their binary
| attachments. Once all the attachments are received, these messages
| are then processed. Prior to version 5.16.4, an attacker can submit
| a binary message and intentionally omit sending one or more of its
| attachments to cause the message along with the partial list of
| received attachments to stay in memory for a long time. Version
| 5.16.4 takes the following measures to address this issue: Binary
| packets are only accepted from authenticated clients and, when a
| client disconnects, the server checks if there is a partial binary
| message being held for the client and deletes it.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48804
https://www.cve.org/CVERecord?id=CVE-2026-48804
[1] https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
[2] https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144515#10
Date:
2026-08-17 19:21:21 UTC
From:
To:
Ack.

thanks,

Em 16/08/2026 09:58, Salvatore Bonaccorso escreveu:

#1144515#15
Date:
2026-10-03 14:34:01 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-socketio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144515@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Paulo Henrique de Lima Santana (phls) <phls@debian.org> (supplier of updated python-socketio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 03 Oct 2026 10:21:56 -0300
Source: python-socketio
Architecture: source
Version: 5.17.0-1
Distribution: unstable
Urgency: medium
Maintainer: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Changed-By: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Closes: 1144515
Changes:
 python-socketio (5.17.0-1) unstable; urgency=medium
 .
   * New upstream version 5.17.0. (Closes: #1144515).
       - Fix bugs reported on CVE-2026-48804.
   * debian/control:
       - Bumped Standards-Version to 4.7.4.
       - Bumped debhelper to 14.
       - Remove redundant priority optional field.
   * debian/copyright:
       - Added new upstream files to the list.
       - Updated upstream and package copyright years.
   * debian/manpage: updated manpage copied from upstream.
Checksums-Sha1:
 01ec9b9a9feef111c90ccd5211eecb3a4490d0f3 2336 python-socketio_5.17.0-1.dsc
 9b7671186b3a42f53d455127a9323a139723cb9a 134574 python-socketio_5.17.0.orig.tar.gz
 5fc1da7160c825720e3f070af11ecfc4a62efe41 35528 python-socketio_5.17.0-1.debian.tar.xz
 1861ffaeb406219f905e0d8cb282e3bbfee027d9 8030 python-socketio_5.17.0-1_source.buildinfo
Checksums-Sha256:
 ade47a9d7dbaec7772518527aa6cbce168a849214f15b20b97cfabe487311082 2336 python-socketio_5.17.0-1.dsc
 c3bbfc4937dcfea7c4d1b182afa94d4a30335d153987e8f2078b344beacf95a0 134574 python-socketio_5.17.0.orig.tar.gz
 7ad7475bb0525517f013776bb10c72c043a79f8f0f286011b7736a75f2e45f89 35528 python-socketio_5.17.0-1.debian.tar.xz
 e7a1c5f350f9957ccb94653877324f2c320acb170a87db379f1948174090d03d 8030 python-socketio_5.17.0-1_source.buildinfo
Files:
 7e1b51c3d2de5c5e3310e711da614423 2336 python optional python-socketio_5.17.0-1.dsc
 dc6b5c68686cf88a4919e83fc0896719 134574 python optional python-socketio_5.17.0.orig.tar.gz
 b7ea5185ff79ea2ef221b6d35b1b723f 35528 python optional python-socketio_5.17.0-1.debian.tar.xz
 fcfee1b04fa68da9f8866dfda90c5783 8030 python optional python-socketio_5.17.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEQySpKy57hdp/nJxAxm0GtARDxFAFAmrBDL0ACgkQxm0GtARD
xFDI3xAAqs/awaJMazyLTgWhmFejl8y+S4bRmI7PSa6cu2cYv1InL0U/hZzoN/Ct
zdwf0+rZzo0CXBk5zsGZTFhSxWjA6Sh2xVa6DPlPHC8Zeou2QtDcwwLbsSxmVDyV
76RqJo0tMFgzqTP/SAfWnB8l0FDFaWgJM0OMRwb4/S2DiHIuPco2HBWKc8OhiG8d
bL7H5EGI9yJvCEZGgYU/TorFNbrKw5tFDrlik9oW+mw09e0cAiqUDcWAaEHo1nwF
aS1Qdjf8XqN/exe0I5IT+EYfmeAEVMAihryuEN42We/5urjc1LBMXQWAfEw4PDum
+J6pJQbZfT9FcyfSidIZTdQcaQfyq1dNhIdmzniuotPXE01fekEH6iJuLtE0QoXT
2jZUGjWZUeZ3s+pQqM61A09DATQC9jXGgQbfXpiEAoW2GgDnmdjlzzh56wuc+bDu
uyyoBnGd3HwS3LY1wD9AtTUoQAGKmKNWDWrmOgQq6AUUgQL2Reei/bNBwj3mH63R
2TOJmHO9IUcrpSfUm+q9wI3jTmhJGG5MXuTxUyjv2JBf0FGaQuXSNKL3Uq/C1YHf
fIkqa7eLYhMoL16i5hd2z1iRbw6j4Jy9gN4/J9MO0wJ+6/GsJDiK79SwgB85aGDm
Vp/4Yu3RBodBhr0HptmcaFNsdVsW0ZXwELciZbHrUEp+5CVhQJQ=
=XN33
-----END PGP SIGNATURE-----