CVSS 3.1 Score 7.3 of 10 (high)


Published Jun 19, 2024
Updated: Jun 20, 2024
CWE ID 754


CVE-2024-38355 is a vulnerability affecting Socket.IO, an open source communication framework. A specially crafted Socket.IO packet can cause an uncaught exception on the Socket.IO server, leading to the termination of the Node.js process. The issue has been fixed in versions `[email protected]` and `2.x` branch with specific commits. Users are advised to upgrade to the fixed versions. If upgrading is not possible, attaching a listener for the "error" event can help catch these errors. The vulnerability has a base severity of HIGH according to the CVSS score and poses a potential danger to organizations using affected versions of Socket.IO as it can lead to service disruption and compromise system integrity and confidentiality.

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.


Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-38355 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions