{"api_version":"v1","generated_at":"2026-10-04T22:45:00+00:00","product":{"cve_count":3,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-socketio-engine-io-eb299ef2f863","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/engine.io","name":"engine.io","next_cursor":null,"observations":[{"affected":">= 5.1.0, < 6.4.2","affected_versions_present":true,"cve_id":"CVE-2023-31125","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-31125","fixed":"6.4.2","last_modified":"2025-02-13T16:49:44.361Z","patch_url":"https://github.com/socketio/engine.io/commit/fc480b4f305e16fe5972cf337d055e598372dc44","primary_source":"","published":"2023-05-08T20:21:01.341Z"},{"affected":"< 3.6.1; >= 4.0.0, < 6.2.1","affected_versions_present":true,"cve_id":"CVE-2022-41940","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-41940","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2025-04-22T16:02:20.459Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-41940","primary_source":"","published":"2022-11-22T00:00:00.000Z"},{"affected":">= 4.0.0, < 4.1.2; >= 5.0.0, < 5.2.1; >= 6.0.0, < 6.1.1","affected_versions_present":true,"cve_id":"CVE-2022-21676","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21676","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T19:13:15.800Z","patch_url":"https://github.com/socketio/engine.io/commit/66f889fc1d966bf5bfa0de1939069153643874ab","primary_source":"","published":"2022-01-12T18:25:15.000Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"socketio"}}
