What is CVE-2026-48802?
CVE-2026-48802 is a vulnerability in python-engineio where the heartbeat mechanism can be exploited to create unnecessary background threads on the server, potentially exhausting resources. It affects versions prior to 4.13.2, and updating is recommended.
Azərbaycanca: CVE-2026-48802 python-engineio server-də ürək döyüntüsü mexanizmi vasitəsilə lazımsız fon thread-lərinin yaradılmasına səbəb olan zəiflikdir. Bu, server resurslarının tükənməsinə gətirib çıxara bilər. 4.13.2 versiyasına qədər təsir edir, yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
How does CVE-2026-48802 affect the python-engineio server?
This vulnerability allows the heartbeat mechanism to create unnecessary background threads on the server, potentially leading to resource exhaustion.
Which version should I update to in order to protect against CVE-2026-48802?
To protect against this vulnerability, it is recommended to update python-engineio to version 4.13.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.