Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Resource exhaustion in engine.io dependency from npm audit #1926

Closed
zachleat opened this issue Feb 10, 2022 · 2 comments · Fixed by #1936
Closed

Resource exhaustion in engine.io dependency from npm audit #1926

zachleat opened this issue Feb 10, 2022 · 2 comments · Fixed by #1936

Comments

@zachleat
Copy link

Report at GHSA-j4f2-536g-r55m

https://www.npmjs.com/package/socket.io is currently at 4.4.x but this package is using 2.4.x

"socket.io": "2.4.0",

@ludofischer
Copy link

According to the migration guides, it would be possible to upgrade the server to 4 while maintaining compatibility with 2.x clients, so keeping the same supported browsers as before. Don't know if that's worth attempting as they mention only dropping support for IE 8.

@lachieh
Copy link
Contributor

lachieh commented Feb 24, 2022

Duplicate issue. See #1850 for original.

This was referenced Mar 13, 2022
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants