Version | socket.io version |
Supported |
---|---|---|
6.x | 4.x | ✅ |
4.x | 3.x | ✅ |
3.5.x | 2.4.x | ✅ |
< 3.5.0 | < 2.4.0 | ❌ |
To report a security vulnerability in this package, please send an email to @darrachequesne (see address in profile) describing the vulnerability and how to reproduce it.
We will get back to you as soon as possible and publish a fix if necessary.
- Feb 2020: Resource exhaustion in engine.io (CVE-2020-36048)
- Jan 2022: Uncaught exception in engine.io (CVE-2022-21676)
- Nov 2022: Uncaught exception in engine.io (CVE-2022-41940)
- May 2023: Uncaught exception in engine.io (CVE-2023-31125)