HIGH7.5
GHSA-xfhh-g9f5-x4m4
Resource exhaustion in socket.io-parser
Quick fix
GHSA-xfhh-g9f5-x4m4 — socket.io-parser: upgrade to the fixed version with the command below.
npm install socket.io-parser@3.3.2Details
The `socket.io-parser` npm package before versions 3.3.2 and 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36049[ADVISORY]
- https://github.com/socketio/socket.io-parser/commit/dcb942d24db97162ad16a67c2a0cf30875342d55[WEB]
- https://blog.caller.xyz/socketio-engineio-dos[WEB]
- https://github.com/bcaller/kill-engine-io[WEB]
- https://github.com/socketio/socket.io-parser/releases/tag/3.3.2[WEB]
- https://github.com/socketio/socket.io-parser/releases/tag/3.4.1[WEB]
- https://www.npmjs.com/package/socket.io-parser[WEB]