We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.
node:events:502 throw err; // Unhandled 'error' event ^ Error [ERR_UNHANDLED_ERROR]: Unhandled error. (undefined) at new NodeError (node:internal/errors:405:5) at Socket.emit (node:events:500:17) at /myapp/node_modules/socket.io/lib/socket.js:531:14 at process.processTicksAndRejections (node:internal/process/task_queues:77:11) { code: 'ERR_UNHANDLED_ERROR', context: undefined }
4.6.2...latest
3.0.0...4.6.1
[email protected]
2.3.0...2.5.0
This issue is fixed by socketio/socket.io@15af22f, included in [email protected] (released in May 2023).
The fix was backported in the 2.x branch today: socketio/socket.io@d30630b
As a workaround for the affected versions of the socket.io package, you can attach a listener for the "error" event:
socket.io
io.on("connection", (socket) => { socket.on("error", () => { // ... }); });
If you have any questions or comments about this advisory:
Thanks a lot to Paul Taylor for the responsible disclosure.
Manifest Path: src/gallery-model-sync-socket/tests/example/package.json
Please look at dependabot report: https://github.com/swipely/yui3-gallery/security/dependabot/12
The text was updated successfully, but these errors were encountered:
ls-barnaby-claydon
No branches or pull requests
Description
Impact
A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.
Affected versions
4.6.2...latest
3.0.0...4.6.1
[email protected]
(at least)2.3.0...2.5.0
[email protected]
Patches
This issue is fixed by socketio/socket.io@15af22f, included in
[email protected]
(released in May 2023).The fix was backported in the 2.x branch today: socketio/socket.io@d30630b
Workarounds
As a workaround for the affected versions of the
socket.io
package, you can attach a listener for the "error" event:For more information
If you have any questions or comments about this advisory:
Thanks a lot to Paul Taylor for the responsible disclosure.
References
Informations
Manifest Path: src/gallery-model-sync-socket/tests/example/package.json
Please look at dependabot report: https://github.com/swipely/yui3-gallery/security/dependabot/12
The text was updated successfully, but these errors were encountered: