- Package:
- src:python-engineio
- Source:
- src:python-engineio
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-02 16:21:03 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for python-engineio. CVE-2026-48802[0]: | python-engineio is a Python implementation of the Engine.IO realtime | client and server. Prior to version 4.13.2, an attacker can cause | the creation of unnecessary background threads in the python- | engineio server by exploiting the heartbeat mechanism, which | launches a thread when a new connection is received, and when the | client sends a PONG packet. This issue primarily affects synchronous | servers. Asynchronous servers allocate background tasks instead of | physical threads, which are lightweight and less likely to cause | denial of service. However, the fix that was implemented was also | applied to the asynchronous case. Version 4.13.2 addresses this | issue as follows: The initial background thread (or async task( for | heartbeat management is only launched if a client passes | authentication in the `connect` handler; and the server now ensures | that there is only one background heatbeat thread (or async task) | per client at a given point in time. Out of sequence PONG packets | are now discarded when an active heartbeat thread is already | running. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48802 https://www.cve.org/CVERecord?id=CVE-2026-48802 [1] https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Ack. thanks, Em 16/08/2026 10:00, Salvatore Bonaccorso escreveu:
We believe that the bug you reported is fixed in the latest version of
python-engineio, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144517@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Paulo Henrique de Lima Santana (phls) <phls@debian.org> (supplier of updated python-engineio package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 02 Oct 2026 12:22:16 -0300
Source: python-engineio
Architecture: source
Version: 4.14.0-1
Distribution: unstable
Urgency: medium
Maintainer: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Changed-By: Paulo Henrique de Lima Santana (phls) <phls@debian.org>
Closes: 1144516 1144517
Changes:
python-engineio (4.14.0-1) unstable; urgency=medium
.
* New upstream version 4.14.0. (Closes: #1144517, #1144516).
- Fix bugs reported on CVE-2026-48802 and CVE-2026-48809.
* debian/control:
- Bumped Standards-Version to 4.7.4.
- Bumped debhelper to 14.
- Remove redundant priority optional field.
* debian/copyright: updated upstream and package copyright years.
* debian/manpage: updated manpage copied from upstream.
Checksums-Sha1:
3f32797ea8aaff06503f836b61e243f7ec2b0b37 2244 python-engineio_4.14.0-1.dsc
507b85d53695666d6c0d73f1593af41c39960d59 80863 python-engineio_4.14.0.orig.tar.gz
2925162e319937d48748aed650cf9a5f68efb67b 30036 python-engineio_4.14.0-1.debian.tar.xz
c9915a89505b1e31b3fc56f64ec775f2ab2165f0 7920 python-engineio_4.14.0-1_source.buildinfo
Checksums-Sha256:
f8d834170c03b0e5eb82db13f005a580a0c6e129f8982dbd21ddab8289dc0b90 2244 python-engineio_4.14.0-1.dsc
eaa1e386baf9c2c7959eef7f9d9165c5ea910c5b392f5316e78d29ed073cb43d 80863 python-engineio_4.14.0.orig.tar.gz
e660dd8a6b4c9b1587cdd3e734a0f64d9f8cbf6f47c8d48a99f7c689e438f9f5 30036 python-engineio_4.14.0-1.debian.tar.xz
f74c1fed02abfde661a65c0d540e1db292f7f93f6cb3fdaa31d7e077bdeda999 7920 python-engineio_4.14.0-1_source.buildinfo
Files:
3bf7d4de412399b7500082c0decadb31 2244 python optional python-engineio_4.14.0-1.dsc
0fd780d7f07b5007be10e3687ff8d7b4 80863 python optional python-engineio_4.14.0.orig.tar.gz
c05d27a0699a43bc720024a3508ad57b 30036 python optional python-engineio_4.14.0-1.debian.tar.xz
440b0c10230d35e6d3b6603955f7df72 7920 python optional python-engineio_4.14.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEQySpKy57hdp/nJxAxm0GtARDxFAFAmq/1B4ACgkQxm0GtARD
xFBQBRAAmD0fOfeuiek8LryREJ+szzlWfxgAc71gyzPLKi/mJFtE6aUPTyxrCci1
Y/l1XUthpmmU+4MtpRu4qL/n4YbAIdQw31pXgbIY9fUYtMAWVP1WiN5xzXFUIaal
+P74bQ0O4UU1c7BTf6RMND/1aWvGxXeCFszNoujiNxpmxGTBRY/A4+y42/BJIjn3
hHMUecAwscQDd1UI+ftBs5/OOZ61LNX0xSVhGjbS6X5j2q1HUaCURCv9ULmvjO7Q
OmE6R4dLJvlyEIO4RaZa/JrbD/lDWVyPrTovt32V+ZHcZYiuoyxnmM+toyJ7yvFU
jUQdqpeZB1mDoaDRTp6hDOlbIbtFPAU4DqxgAV/6ya2sSQ/O19UkhHh9xDGa8oNa
KqOpLjsx1ODkxYunsaZJ+hAJGLI8zmXCbWpmVfsmy/O8zaudqZRfwtfjLndiclTY
4xsA1kCft+ZCPKuHziaC8ZW258oXoMnjfY+pDLjww4Yv5XuAbk8kVFWvYIz+i5Is
sQ5h2US+PraGa5m7k+5C3/o9q5aSkUr49yS9neQgYjouyqrwHHw3btyrbakngFO1
7u16D3osnz0ib0HkdQWH4mhlQKw42C36WhvWxL2CX8pErFyWtAsbQWcnywfVD4+c
6a6ocSusrkvUJMr7yM1QMLBi/ODoBJ8htPn0sBcP/B0LxtU57t0=
=xbEb
-----END PGP SIGNATURE-----