Debian Package Tracker
Register | Log in
Subscribe

python-socketio

python3 implementation of the Socket.IO realtime client and server

Choose email to subscribe with

general
  • source: python-socketio (main)
  • version: 5.17.0-1
  • maintainer: Paulo Henrique de Lima Santana (phls) (DMD)
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.0.3-2
  • oldstable: 5.7.2-2
  • stable: 5.12.1-1
  • testing: 5.16.0-1
  • unstable: 5.17.0-1
versioned links
  • 5.0.3-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.7.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.12.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.16.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.17.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-socketio
action needed
Marked for autoremoval on 12 November due to ipywidgets: #1149422 high
Version 5.16.0-1 of python-socketio is marked for autoremoval from testing on Thu 12 Nov 2026. It depends (transitively) on ipywidgets, affected by #1149422. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-10-07 Last update: 2026-10-07 01:34
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-48804: python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.
Created: 2026-10-03 Last update: 2026-10-04 01:32
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-05-20 Last update: 2026-01-22 06:01
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2025-61765: (needs triaging) python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerability in python-socketio versions prior to 5.14.0 allows attackers to execute arbitrary Python code through malicious pickle deserialization in multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications. When Socket.IO servers are configured to use a message queue backend such as Redis for inter-server communication, messages sent between the servers are encoded using the `pickle` Python module. When a server receives one of these messages through the message queue, it assumes it is trusted and immediately deserializes it. The vulnerability stems from deserialization of messages using Python's `pickle.loads()` function. Having previously obtained access to the message queue, the attacker can send a python-socketio server a crafted pickle payload that executes arbitrary code during deserialization via Python's `__reduce__` method. This vulnerability only affects deployments with a compromised message queue. The attack can lead to the attacker executing random code in the context of, and with the privileges of a Socket.IO server process. Single-server systems that do not use a message queue, and multi-server systems with a secure message queue are not vulnerable. In addition to making sure standard security practices are followed in the deployment of the message queue, users of the python-socketio package can upgrade to version 5.14.0 or newer, which remove the `pickle` module and use the much safer JSON encoding for inter-server messaging.
  • CVE-2026-48804: (needs triaging) python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` messages in memory while it waits to receive their binary attachments. Once all the attachments are received, these messages are then processed. Prior to version 5.16.4, an attacker can submit a binary message and intentionally omit sending one or more of its attachments to cause the message along with the partial list of received attachments to stay in memory for a long time. Version 5.16.4 takes the following measures to address this issue: Binary packets are only accepted from authenticated clients and, when a client disconnects, the server checks if there is a partial binary message being held for the client and deletes it.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-10-07 Last update: 2026-10-04 01:32
testing migrations
  • excuses:
    • Migrates after: python-engineio
    • Migration status for python-socketio (5.16.0-1 to 5.17.0-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 3 of 5 days old
    • ∙ ∙ Build-Depends(-Arch): python-socketio python-engineio
    • ∙ ∙ Depends: python-socketio python-engineio
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/p/python-socketio.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-03] Accepted python-socketio 5.17.0-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2026-01-06] python-socketio 5.16.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-30] Accepted python-socketio 5.16.0-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2025-08-13] python-socketio 5.13.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-19] Accepted python-socketio 5.13.0-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2025-03-31] python-socketio 5.12.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-11] Accepted python-socketio 5.12.1-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2024-12-24] python-socketio 5.11.2-1.1 MIGRATED to testing (Debian testing watch)
  • [2024-12-18] Accepted python-socketio 5.11.2-1.1 (source) into unstable (Alexandre Detiste)
  • [2024-04-20] python-socketio 5.11.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-11] Accepted python-socketio 5.11.2-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2023-01-21] python-socketio 5.7.2-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-19] Accepted python-socketio 5.7.2-2 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2023-01-18] python-socketio 5.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-15] Accepted python-socketio 5.7.2-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2020-12-27] python-socketio 5.0.3-2 MIGRATED to testing (Debian testing watch)
  • [2020-12-24] Accepted python-socketio 5.0.3-2 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2020-12-24] Accepted python-socketio 5.0.3-1 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2020-01-12] python-socketio 4.4.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-01-09] Accepted python-socketio 4.4.0-2 (source) into unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
  • [2019-12-27] Accepted python-socketio 4.4.0-1 (source all) into unstable, unstable (Paulo Henrique de Lima Santana (phls)) (signed by: Paulo Henrique de Lima Santana)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 5.16.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing