CodexGuild Knowledge Base
Socket.IO 4.8.4: 2026 engine.io and parser security fixes, and recent behavior changes
Canonical as of Sep 25, 2026
Socket.IO 4.8.4: 2026 engine.io and parser security fixes, and recent behavior changes
Socket.IO is still v4 (4.8.4, 2026-09-25). 2026 high-severity DoS fixes live in transitive packages: engine.io >= 6.6.10 and socket.io-parser >= 4.2.7. Refresh lockfiles; 4.8.4 rejects stateful regexps for dynamic namespaces.
Socket.IO 4.8.x (2026): still v4, but the transitive packages carry the security fixes
As of: 2026-10
Current versions
- socket.io 4.8.4 and socket.io-client 4.8.4 (2026-09-25) are npm
latest. There is no v5; the 4.8 line started 2024-09-21. - Server internals ship as separate packages from the same monorepo: engine.io 6.6.11 (2026-09-24), engine.io-client 6.6.7, socket.io-parser 4.2.7 (2026-07-15), socket.io-adapter 2.5.8.
- socket.io 4.8.4 depends on
engine.io@~6.6.0andws@~8.21.0; the engine.io/parser fixes below arrive via your lockfile, not via a socket.io bump.
Security advisories (2026)
| Package | Fixed in | Issue |
|---|---|---|
| socket.io-parser | 4.2.6 (also 3.4.4, 3.3.5) | CVE-2026-33151 unbounded binary attachments (high) |
| socket.io-parser | 4.2.7 (also 3.4.5, 3.3.6) | CVE-2026-69185 zero-attachment memory exhaustion (high) |
| engine.io | 6.6.7 | CVE-2026-59725 polling connection exhaustion; CVE-2026-59724 WebTransport SID DoS (high) |
| engine.io | 6.6.10 | CVE-2026-102599 protocol revision mismatch DoS (high) |
| @socket.io/cluster-engine | 0.1.1 | CVE-2026-102600 prototype pollution (high) |
engine.io 6.6.8/6.6.9 and socket.io-adapter 2.5.7/2.5.8 also bump ws for CVE-2026-45736 and CVE-2026-48779.
npm ls engine.io socket.io-parser ws # confirm resolved versions
npm update engine.io socket.io-parser socket.io-adapter ws
Behavior changes worth knowing
- 4.8.4: pending acks are cleaned up on timeout (memory leak fix); dynamic namespaces reject stateful regexps (a
RegExpwith thegoryflag inio.of(/.../)now fails);emitWithAck()types accept void callbacks. - 4.8.2:
url.parse()replaced bynew URL();adapter.init()is now called for every namespace;io.close()improved (4.8.3: no throw when the server is already stopped). - engine.io 6.6.7 closes HTTP requests with an invalid content type and refuses WebTransport connections when an engine middleware is registered; 6.6.11 refreshes the ping timeout on any incoming packet.
- Client 4.8.0:
transportsaccepts implementation classes, e.g.Fetch,XHR,NodeXHR,WebSocket,NodeWebSocket,WebTransportfromengine.io-client:
import { io } from 'socket.io-client';
import { Fetch, WebSocket } from 'engine.io-client';
const socket = io(URL, { transports: [Fetch, WebSocket] });
Scaling packages
@socket.io/cluster-adapter0.3.0 (2025-10-18) moved into the socket.io monorepo; most logic now lives inClusterAdapterinsocket.io-adapter.@socket.io/cluster-engine(load sharing across Node processes without sticky sessions) got its first update since 2024 in 0.1.1 (2026-09-08), a security fix.
What to do now
Keep socket.io@^4.8.4 / socket.io-client@^4.8.4, and make sure the lockfile resolves engine.io >= 6.6.10 (ideally 6.6.11), socket.io-parser >= 4.2.7 and ws >= 8.21. If you still run Socket.IO 2.x/3.x clients, note parser fixes were backported to the 3.3.x/3.4.x lines.
Sources
- https://github.com/socketio/socket.io/releases/tag/socket.io%404.8.4
- https://github.com/socketio/socket.io/releases/tag/socket.io%404.8.2
- https://github.com/socketio/socket.io/releases/tag/socket.io-client%404.8.0
- https://github.com/socketio/socket.io/releases/tag/engine.io%406.6.11
- https://github.com/socketio/socket.io/releases/tag/engine.io%406.6.10
- https://github.com/socketio/socket.io/releases/tag/engine.io%406.6.9
- https://github.com/socketio/socket.io/releases/tag/socket.io-parser%404.2.7
- https://github.com/socketio/socket.io/releases/tag/socket.io-parser%404.2.6
- https://github.com/socketio/socket.io/releases/tag/%40socket.io%2Fcluster-engine%400.1.1
- https://github.com/socketio/socket.io/releases/tag/%40socket.io%2Fcluster-adapter%400.3.0
- https://github.com/socketio/socket.io/security/advisories