CVE-2026-48809
Last modified
CVE-2026-48809 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory.
Description
python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of the python-engineio server in which the size of incoming messages is not checked before the messages are loaded into memory. An attacker can take advantage of these to cause unnecessary memory allocations in the python-engineio server. The two cases are POST requests, when using ASGI with the long polling transport and WebSocket messages, when using Aiohttp with the WebSocket transport. Version 4.13.2 addresses this issue. ASGI severs now only load the body of incoming requests into memory after the client is confirmed to be known and authenticated, and the payload size is below the maximum allowed size. Requests that do not comply with these requirements are discarded. Aiohttp servers configure the maximum payload size in the underlying WebSocket layer from Aiohttp, so that large messages are discarded by Aiohttp before they are delivered to python-engineio.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| miguelgrinberg | python-engineio | < 4.13.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48809?
How severe is CVE-2026-48809?
How do I fix CVE-2026-48809?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48802python-engineio is a Python implementation of the Engine.IO …7.5
- CVE-2026-48804python-socketio is a Python implementation of the Socket.IO …7.5
- CVE-2026-48805Twig is a template language for PHP. Prior to 3.27.0, deprec…9.1
- CVE-2026-48806Twig is a template language for PHP. Prior to 3.27.0, ArrayE…9.1
- CVE-2026-48807Twig is a template language for PHP. Prior to 3.27.0, the sa…9.1
- CVE-2026-48808Twig is a template language for PHP. Prior to 3.27.0, the co…7.5
- CVE-2026-4881In affected versions of Octopus Server, permissions were not…6.5
- CVE-2026-48810FreeScout is a free help desk and shared inbox built with PH…4.3
- CVE-2026-48811FreeScout is a free help desk and shared inbox built with PH…4.3
- CVE-2026-48812FreeScout is a free help desk and shared inbox built with PH…7.5
- CVE-2026-48813Flawfinder is a a static analysis tool for finding vulnerabi…8.7
- CVE-2026-48814Network-AI is a TypeScript/Node.js multi-agent orchestrator.…9.1
Are you affected by CVE-2026-48809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
