What is CVE-2026-48809?
CVE-2026-48809 is a vulnerability in python-engineio versions prior to 4.13.2, where specific server configurations fail to check incoming message sizes before loading them into memory. A remote attacker can exploit this by sending large messages, leading to a potential Denial of Service (DoS) condition. Users are strongly advised to upgrade to version 4.13.2 immediately.
Azərbaycanca: CVE-2026-48809, python-engineio kitabxanasında 4.13.2 versiyasından əvvəlki versiyalarda aşkar edilmiş zəiflikdir. Server müəyyən konfiqurasiyalarda işləyərkən daxil olan mesajların ölçüsü yoxlanılmadığı üçün, uzaqdan hücum edən şəxs böyük mesaj göndərərək yaddaşda "Denial of Service" (DoS) vəziyyəti yarada bilər. İstifadəçilərə kitabxananı təcili olaraq 4.13.2 versiyasına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which library was CVE-2026-48809 discovered and what versions are affected?
The vulnerability was discovered in the python-engineio library in versions prior to 4.13.2.
What impact can a remote attacker cause by exploiting CVE-2026-48809?
By exploiting the lack of incoming message size checks, a remote attacker can send large messages, leading to a Denial of Service (DoS) condition in memory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.