Allocation of Resources Without Limits or Throttling in Python Engine.IO - #VU132251
Published: May 25, 2026
Python Engine.IO
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the python-engineio server when handling POST requests with ASGI long polling or WebSocket messages with Aiohttp WebSocket transport. A remote attacker can send oversized messages to cause a denial of service.
The issue occurs only in two specific server configurations: ASGI with the long polling transport, and Aiohttp with the WebSocket transport.