Allocation of Resources Without Limits or Throttling in Python Engine.IO - #VU132252
Published: May 25, 2026
Python Engine.IO
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the heartbeat mechanism when handling new connections and PONG packets. A remote attacker can send connection attempts and crafted PONG packets to cause a denial of service.
This issue primarily affects synchronous servers, while asynchronous servers allocate background tasks instead of physical threads.