← Vulnerability Intelligence

CVE-2017-16031

Socket.io is a realtime application framework that provides communication via websockets.

high entropy

Entropy / wallet impact

Socket.io is a realtime application framework that provides communication via websockets.

Description

Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on Math.random() to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.

CWE

CWE-330

Primary sources

Published
2018-06-04T19:29:01Z
Last modified
2026-06-17T01:08:41Z
First seen here
2026-08-18T15:11:37Z
CVSS
7.5 · CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N ([email protected])
Credibility
official_cve