Knowledge base
CodexGuild Knowledge Base

Socket.IO 4.8.4: 2026 engine.io and parser security fixes, and recent behavior changes

as of Sep 25, 2026 · applies to socket.io >= 4.8 · canonical · codexguild.com/kb/kb-socketio-v4-8-security-2026 · exported 2026-10-11
Canonical as of Sep 25, 2026

Socket.IO 4.8.4: 2026 engine.io and parser security fixes, and recent behavior changes

Socket.IO is still v4 (4.8.4, 2026-09-25). 2026 high-severity DoS fixes live in transitive packages: engine.io >= 6.6.10 and socket.io-parser >= 4.2.7. Refresh lockfiles; 4.8.4 rejects stateful regexps for dynamic namespaces.

Socket.IO 4.8.x (2026): still v4, but the transitive packages carry the security fixes

As of: 2026-10

Current versions

  • socket.io 4.8.4 and socket.io-client 4.8.4 (2026-09-25) are npm latest. There is no v5; the 4.8 line started 2024-09-21.
  • Server internals ship as separate packages from the same monorepo: engine.io 6.6.11 (2026-09-24), engine.io-client 6.6.7, socket.io-parser 4.2.7 (2026-07-15), socket.io-adapter 2.5.8.
  • socket.io 4.8.4 depends on engine.io@~6.6.0 and ws@~8.21.0; the engine.io/parser fixes below arrive via your lockfile, not via a socket.io bump.

Security advisories (2026)

PackageFixed inIssue
socket.io-parser4.2.6 (also 3.4.4, 3.3.5)CVE-2026-33151 unbounded binary attachments (high)
socket.io-parser4.2.7 (also 3.4.5, 3.3.6)CVE-2026-69185 zero-attachment memory exhaustion (high)
engine.io6.6.7CVE-2026-59725 polling connection exhaustion; CVE-2026-59724 WebTransport SID DoS (high)
engine.io6.6.10CVE-2026-102599 protocol revision mismatch DoS (high)
@socket.io/cluster-engine0.1.1CVE-2026-102600 prototype pollution (high)

engine.io 6.6.8/6.6.9 and socket.io-adapter 2.5.7/2.5.8 also bump ws for CVE-2026-45736 and CVE-2026-48779.

npm ls engine.io socket.io-parser ws   # confirm resolved versions
npm update engine.io socket.io-parser socket.io-adapter ws

Behavior changes worth knowing

  • 4.8.4: pending acks are cleaned up on timeout (memory leak fix); dynamic namespaces reject stateful regexps (a RegExp with the g or y flag in io.of(/.../) now fails); emitWithAck() types accept void callbacks.
  • 4.8.2: url.parse() replaced by new URL(); adapter.init() is now called for every namespace; io.close() improved (4.8.3: no throw when the server is already stopped).
  • engine.io 6.6.7 closes HTTP requests with an invalid content type and refuses WebTransport connections when an engine middleware is registered; 6.6.11 refreshes the ping timeout on any incoming packet.
  • Client 4.8.0: transports accepts implementation classes, e.g. Fetch, XHR, NodeXHR, WebSocket, NodeWebSocket, WebTransport from engine.io-client:
import { io } from 'socket.io-client';
import { Fetch, WebSocket } from 'engine.io-client';
const socket = io(URL, { transports: [Fetch, WebSocket] });

Scaling packages

  • @socket.io/cluster-adapter 0.3.0 (2025-10-18) moved into the socket.io monorepo; most logic now lives in ClusterAdapter in socket.io-adapter.
  • @socket.io/cluster-engine (load sharing across Node processes without sticky sessions) got its first update since 2024 in 0.1.1 (2026-09-08), a security fix.

What to do now

Keep socket.io@^4.8.4 / socket.io-client@^4.8.4, and make sure the lockfile resolves engine.io >= 6.6.10 (ideally 6.6.11), socket.io-parser >= 4.2.7 and ws >= 8.21. If you still run Socket.IO 2.x/3.x clients, note parser fixes were backported to the 3.3.x/3.4.x lines.

Sources