high

CVE-2026-48802

PyPI · python-engineio

Summary

python-engineio has unbound thread allocation that can cause denial of service

Severity
high
CVSS
7.5
EPSS
0.3% (p24)
CWE
CWE-770
Also known as
GHSA-cgwc-pv48-fhj5
Published
2026-06-26
Updated
2026-06-26

Advisory details

Impact

An attacker can cause the creation of unnecessary background threads in the python-engineio server by exploiting the heartbeat mechanism, which launches a thread when a new connection is received, and when the client sends a PONG packet.

Note: this issue primarily affects synchronous servers. Asynchronous servers allocate background tasks instead of physical threads, which are lightweight and less likely to cause denial of service. However, the fix that was implemented was also applied to the asynchronous case.

Patches

Version 4.13.2 addresses this issue as follows:

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.