#1144516 python-engineio: CVE-2026-48809

Package:
src:python-engineio
Source:
src:python-engineio
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 16:21:02 UTC
Severity:
normal
Tags:
#1144516#5
Date:
2026-08-16 13:00:07 UTC
From:
To:
Hi,

The following vulnerability was published for python-engineio.

CVE-2026-48809[0]:
| python-engineio is a Python implementation of the Engine.IO realtime
| client and server. Versions prior to 4.13.2 have two specific
| configurations of the python-engineio server in which the size of
| incoming messages is not checked before the messages are loaded into
| memory. An attacker can take advantage of these to cause unnecessary
| memory allocations in the python-engineio server. The two cases are
| POST requests, when using ASGI with the long polling transport and
| WebSocket messages, when using Aiohttp with the WebSocket transport.
| Version 4.13.2 addresses this issue. ASGI severs now only load the
| body of incoming requests into memory after the client is confirmed
| to be known and authenticated, and the payload size is below the
| maximum allowed size. Requests that do not comply with these
| requirements are discarded. Aiohttp servers configure the maximum
| payload size in the underlying WebSocket layer from Aiohttp, so that
| large messages are discarded by Aiohttp before they are delivered to
| python-engineio.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48809
https://www.cve.org/CVERecord?id=CVE-2026-48809
[1] https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144516#10
Date:
2026-08-17 19:21:31 UTC
From:
To:
Ack.

thanks,

Em 16/08/2026 10:00, Salvatore Bonaccorso escreveu:

#1144516#15
Date:
2026-10-02 16:19:56 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-engineio, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144516@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Paulo Henrique de Lima Santana (phls) <phls@debian.org> (supplier of updated python-engineio package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 12:22:16 -0300
Source: python-engineio
Architecture: source
Version: 4.14.0-1
Distribution: unstable
Urgency: medium
Maintainer: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Changed-By: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Closes: 1144516 1144517
Changes:
 python-engineio (4.14.0-1) unstable; urgency=medium
 .
   * New upstream version 4.14.0. (Closes: #1144517, #1144516).
       - Fix bugs reported on CVE-2026-48802 and CVE-2026-48809.
   * debian/control:
       - Bumped Standards-Version to 4.7.4.
       - Bumped debhelper to 14.
       - Remove redundant priority optional field.
   * debian/copyright: updated upstream and package copyright years.
   * debian/manpage: updated manpage copied from upstream.
Checksums-Sha1:
 3f32797ea8aaff06503f836b61e243f7ec2b0b37 2244 python-engineio_4.14.0-1.dsc
 507b85d53695666d6c0d73f1593af41c39960d59 80863 python-engineio_4.14.0.orig.tar.gz
 2925162e319937d48748aed650cf9a5f68efb67b 30036 python-engineio_4.14.0-1.debian.tar.xz
 c9915a89505b1e31b3fc56f64ec775f2ab2165f0 7920 python-engineio_4.14.0-1_source.buildinfo
Checksums-Sha256:
 f8d834170c03b0e5eb82db13f005a580a0c6e129f8982dbd21ddab8289dc0b90 2244 python-engineio_4.14.0-1.dsc
 eaa1e386baf9c2c7959eef7f9d9165c5ea910c5b392f5316e78d29ed073cb43d 80863 python-engineio_4.14.0.orig.tar.gz
 e660dd8a6b4c9b1587cdd3e734a0f64d9f8cbf6f47c8d48a99f7c689e438f9f5 30036 python-engineio_4.14.0-1.debian.tar.xz
 f74c1fed02abfde661a65c0d540e1db292f7f93f6cb3fdaa31d7e077bdeda999 7920 python-engineio_4.14.0-1_source.buildinfo
Files:
 3bf7d4de412399b7500082c0decadb31 2244 python optional python-engineio_4.14.0-1.dsc
 0fd780d7f07b5007be10e3687ff8d7b4 80863 python optional python-engineio_4.14.0.orig.tar.gz
 c05d27a0699a43bc720024a3508ad57b 30036 python optional python-engineio_4.14.0-1.debian.tar.xz
 440b0c10230d35e6d3b6603955f7df72 7920 python optional python-engineio_4.14.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEQySpKy57hdp/nJxAxm0GtARDxFAFAmq/1B4ACgkQxm0GtARD
xFBQBRAAmD0fOfeuiek8LryREJ+szzlWfxgAc71gyzPLKi/mJFtE6aUPTyxrCci1
Y/l1XUthpmmU+4MtpRu4qL/n4YbAIdQw31pXgbIY9fUYtMAWVP1WiN5xzXFUIaal
+P74bQ0O4UU1c7BTf6RMND/1aWvGxXeCFszNoujiNxpmxGTBRY/A4+y42/BJIjn3
hHMUecAwscQDd1UI+ftBs5/OOZ61LNX0xSVhGjbS6X5j2q1HUaCURCv9ULmvjO7Q
OmE6R4dLJvlyEIO4RaZa/JrbD/lDWVyPrTovt32V+ZHcZYiuoyxnmM+toyJ7yvFU
jUQdqpeZB1mDoaDRTp6hDOlbIbtFPAU4DqxgAV/6ya2sSQ/O19UkhHh9xDGa8oNa
KqOpLjsx1ODkxYunsaZJ+hAJGLI8zmXCbWpmVfsmy/O8zaudqZRfwtfjLndiclTY
4xsA1kCft+ZCPKuHziaC8ZW258oXoMnjfY+pDLjww4Yv5XuAbk8kVFWvYIz+i5Is
sQ5h2US+PraGa5m7k+5C3/o9q5aSkUr49yS9neQgYjouyqrwHHw3btyrbakngFO1
7u16D3osnz0ib0HkdQWH4mhlQKw42C36WhvWxL2CX8pErFyWtAsbQWcnywfVD4+c
6a6ocSusrkvUJMr7yM1QMLBi/ODoBJ8htPn0sBcP/B0LxtU57t0=
=xbEb
-----END PGP SIGNATURE-----