Vulnerabilities/

Socket.IO: Zero-attachment Memory Exhaustion

Severity:
High

Description

A specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory.

Recommendation

Update the socket.io-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
socket.io-parser
Anything's wrong? Let us know Last updated on August 03, 2026