{"id":"CVE-2017-16031","aliases":["GHSA-qv2v-m59f-v5fw"],"url":"https://o3.security/vulnerability/CVE-2017-16031","summary":"Insecure randomness in socket.io","details":"Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.","published":"2018-06-04T19:29:01.727Z","modified":"2026-07-08T05:48:48.196151431Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"socket.io","fixedVersion":"0.9.7"}],"fix":{"url":"https://github.com/socketio/socket.io/commit/67b4eb9abdf111dfa9be4176d1709374a2b4ded8","label":"socketio/socket.io@67b4eb9"},"references":[{"type":"ADVISORY","url":"https://nodesecurity.io/advisories/321"},{"type":"REPORT","url":"https://github.com/socketio/socket.io/issues/856"},{"type":"REPORT","url":"https://github.com/socketio/socket.io/pull/857"},{"type":"FIX","url":"https://github.com/socketio/socket.io/commit/67b4eb9abdf111dfa9be4176d1709374a2b4ded8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:48:48.196151431Z"}}