CVE-2022-41940 - CVE House
Back to Database
Status published High CVE-2022-41940

Uncaught exception in engine.io

Vulnerability Description

Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the users of the engine.io package, including those who uses depending packages like socket.io. There is no known workaround except upgrading to a safe version. There are patches for this issue released in versions 3.6.1 and 6.2.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-41940

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

engine.io
Vulnerable Versions:
< 3.6.1, >= 4.0.0, < 6.2.1

Timeline

Official Publish: November 22nd, 2022
Last Modified: April 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H

Weaknesses (CWE)