Vulnerabilities/

tRPC 11 WebSocket DoS Vulnerability

Severity:
High

Description

An unhandled error is thrown when validating invalid connectionParams which crashes a tRPC WebSocket server. This allows any unauthenticated user to crash a tRPC 11 WebSocket server.

Recommendation

Update the @trpc/server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@trpc/server
Anything's wrong? Let us know Last updated on April 24, 2025

This issue is available in SmartScanner Professional

See Pricing