Allocation of Resources Without Limits or Throttling in Python Engine.IO - CVE-2026-48802
Published: May 25, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the heartbeat mechanism when handling new connections and PONG packets. A remote attacker can send connection attempts and crafted PONG packets to cause a denial of service.
This issue primarily affects synchronous servers, while asynchronous servers allocate background tasks instead of physical threads.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
Python 3 Module
openSUSE Leap
python311-python-engineio
How to mitigate CVE-2026-48802
python311-python-engineio - update to 4.3.4-150600.3.3.1