socket.io
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting socket.iopage 1 of 1
- CVE-2017-16031HIGHCVSS 7.5EG 7.5✓ Fixed in 0.9.72018-06-04
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket…
- CVE-2020-28481MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.4.02021-01-19
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
- CVE-2024-38355HIGHCVSS 7.3EG 7.3✓ Fixed in 4.6.22024-06-19
Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fi…
Check whether socket.io is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for socket.io CVEs against the assets you own.
Start Free Scan →