CVE-2022-21676: Uncaught Exception in engine.io
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package starting from version 4.0.0, including those who uses depending packages like socket.io. Versions prior to 4.0.0 are not impacted. A fix has been released for each major branch, namely 4.1.2 for the 4.x.x branch, 5.2.1 for the 5.x.x branch, and 6.1.1 for the 6.x.x branch. There is no known workaround except upgrading to a safe version.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-21676?
CVE-2022-21676 is a vulnerability in Engine.IO, a transport-based bi-directional communication layer for Socket.IO, where a specially crafted HTTP request can cause an uncaught exception, leading to the termination of the Node.js process.
How does CVE-2022-21676 impact users?
CVE-2022-21676 impacts all users of Socket.Engine.IO and Node.js versions between 4.0.0 and 4.1.2, versions between 5.0.0 and 5.2.1, and versions between 6.0.0 and 6.1.1.
What is the severity of CVE-2022-21676?
CVE-2022-21676 has a severity rating of 7.5 (high).
How can I fix CVE-2022-21676?
To fix CVE-2022-21676, users should update to the latest versions of Socket.Engine.IO and Node.js.
Where can I find more information about CVE-2022-21676?
More information about CVE-2022-21676 can be found in the references provided by Socket.Engine.IO on their GitHub page.