{
  "threat_severity" : "Important",
  "public_date" : "2026-07-08T15:37:52Z",
  "bugzilla" : {
    "description" : "socket.io: engine.io: Socket.IO: Denial of Service via invalid binary POST requests",
    "id" : "2498118",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2498118"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-772",
  "details" : [ "Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO protocol v4 polling transport does not properly close the HTTP response for invalid binary POST requests with Content-Type: application/octet-stream, allowing an unauthenticated attacker to exhaust server-side connections and sockets. This issue is fixed in version 6.6.7.", "A flaw was found in Socket.IO, specifically within the Engine.IO protocol v4 polling transport. An unauthenticated attacker can exploit this vulnerability by sending invalid binary POST requests with a Content-Type of application/octet-stream. This improper handling of requests prevents the HTTP response from being properly closed, which can lead to the exhaustion of server-side connections and sockets. The primary consequence is a Denial of Service (DoS), making the affected service unavailable to legitimate users." ],
  "statement" : "This flaw has been rated as Important. An unauthenticated remote attacker can exploit a vulnerability in the Engine.IO protocol v4 polling transport of Socket.IO by sending malformed binary POST requests. This can lead to server-side connection exhaustion and a denial of service, impacting the availability of applications utilizing Socket.IO.",
  "affected_release" : [ {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-10T00:00:00Z",
    "advisory" : "RHSA-2026:37577",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet8-0-main-8.0.128-1.1.hum1",
    "impact" : "important"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-gaudi-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/bootc-rocm-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI (RHEL AI) 3",
    "fix_state" : "Affected",
    "package_name" : "rhelai3/disk-image-cuda-rhel9",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-59725\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-59725\nhttps://github.com/socketio/socket.io/commit/fc11285e14964c2132d122164bf130c355f60671\nhttps://github.com/socketio/socket.io/releases/tag/engine.io@6.6.7\nhttps://github.com/socketio/socket.io/security/advisories/GHSA-r635-g3xr-vw7x" ],
  "name" : "CVE-2026-59725",
  "csaw" : false
}