Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.4%top 72%

CWE-404: Improper Resource Shutdown or Release in socketio socket.io (CVE-2026-59725)

0
High
Published: 07/08/2026 (07/08/2026, 15:37:52 UTC)
Source: GCVE Database
Vendor/Project: socketio
Product: socket.io

Description

Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

Affected versions
>= 4.1.0, < 6.6.7

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/10/2026, 13:32:29 UTC

Technical Analysis

This Red Hat security advisory (RHSA-2026:37577) addresses vulnerabilities in the dotnet8.0 RPM packages included in Red Hat Hardened Images. The update includes multiple updated RPMs such as aspnetcore-runtime, dotnet-runtime, dotnet-sdk, and related components for aarch64 and x86_64 architectures. The advisory specifically mentions fixes for CVE-2026-59725 and CVE-2026-59869. The advisory does not specify exact affected or fixed versions, nor does it provide a CVSS score. No known exploits have been reported. The advisory directs users to apply the update available via Red Hat's image repository.

Potential Impact

The vulnerabilities addressed by this advisory affect the dotnet8.0 runtime and SDK components within Red Hat Hardened Images. While the exact impact details are not provided, the vendor classifies the severity as high, indicating potential significant security risks if unpatched. No known exploits in the wild have been reported, suggesting limited or no active exploitation at this time.

Mitigation Recommendations

Red Hat has released updated RPM packages for dotnet8.0 components as part of this security advisory. Users should apply these updates by obtaining the latest Hardened Images RPMs from Red Hat's official image repository at https://images.redhat.com/. The vendor advisory does not indicate any temporary mitigations or that no action is required. Patch status is not explicitly confirmed in terms of affected or fixed versions; therefore, users should follow Red Hat's official update instructions to ensure remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:37577
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a50f27368715ace439d58fa

Added to database: 07/10/2026, 13:24:03 UTC

Last enriched: 07/10/2026, 13:32:29 UTC

Last updated: 07/31/2026, 19:24:49 UTC

Views: 96

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses