socket.io-parser - Insufficient validation when decoding a Socket.IO packet #5192
Unanswered
ritikaGupta4
asked this question in
Q&A
Replies: 3 comments 6 replies
-
Hi! Reference: https://github.com/socketio/socket.io-parser/releases/tag/3.3.4
|
Beta Was this translation helpful? Give feedback.
0 replies
-
Do we have any stable version in |
Beta Was this translation helpful? Give feedback.
1 reply
-
No, actually we aren't using |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
What version of socket.io-client are you using?
socket.io-client v2.5.0
GHSA-cqmj-92xf-r6r9
Expected Behavior
The version of socket.io-client doesn't use a vulnerable version of socket.io-parser
Actual Behavior
npm audit report currently shows vulnerabilities.
Beta Was this translation helpful? Give feedback.
All reactions