Allocation of Resources Without Limits or Throttling in Python Engine.IO - CVE-2026-48809
Published: May 25, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the python-engineio server when handling POST requests with ASGI long polling or WebSocket messages with Aiohttp WebSocket transport. A remote attacker can send oversized messages to cause a denial of service.
The issue occurs only in two specific server configurations: ASGI with the long polling transport, and Aiohttp with the WebSocket transport.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
Python 3 Module
openSUSE Leap
python311-python-engineio
How to mitigate CVE-2026-48809
python311-python-engineio - update to 4.3.4-150600.3.3.1