Vulnerabilities/

Uncaught Exception in engine.io - engine.io

Severity:
High

Description

A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.

RangeError: Invalid WebSocket frame: RSV2 and RSV3 must be clear at Receiver.getInfo (/…/node_modules/ws/lib/receiver.js:176:14) at Receiver.startLoop (/…/node_modules/ws/lib/receiver.

Recommendation

Update the engine.io package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
engine.io
Anything's wrong? Let us know Last updated on June 27, 2023