Severity: high
CVE: CVE-2026-59725
Package: engine.io @ 6.6.6
Vulnerable range: >=4.1.0 <6.6.7
Patched in: >=6.6.7
Dep paths:
artifacts__api-server>socket.io>engine.io
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
Reference: GHSA-r635-g3xr-vw7x
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: CVE-2026-59725
Package:
engine.io@6.6.6Vulnerable range:
>=4.1.0 <6.6.7Patched in:
>=6.6.7Dep paths:
artifacts__api-server>socket.io>engine.ioReference: GHSA-r635-g3xr-vw7x
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.