Vulnerabilities/

Resource exhaustion in socket.io-parser

Severity:
High

Description

The socket.io-parser npm package before versions 3.3.2 and 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.

Recommendation

Update the socket.io-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
socket.io-parser
Anything's wrong? Let us know Last updated on February 01, 2023