This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade socket.io from 2.2.0 to 2.5.0.
![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=socket.io&from_version=2.2.0&to_version=2.5.0&pr_id=017efdd1-96b3-4d00-a4ad-940a2ed1d9ed&visibility=true&has_feature_flag=false)
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **4 versions** ahead of your current version.
- The recommended version was released **3 months ago**, on 2022-06-26.
The recommended version fixes:
Severity | Issue | PriorityScore (*) | Exploit Maturity |
:-------------------------:|:-------------------------|-------------------------|:-------------------------
| Access Restriction Bypass [SNYK-JS-XMLHTTPREQUESTSSL-1255647](https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1255647) | **472/1000** **Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept
| Arbitrary Code Injection [SNYK-JS-XMLHTTPREQUESTSSL-1082936](https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936) | **472/1000** **Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept
| Denial of Service (DoS) [SNYK-JS-SOCKETIOPARSER-1056752](https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-1056752) | **472/1000** **Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept
| Regular Expression Denial of Service (ReDoS) [SNYK-JS-WS-1296835](https://snyk.io/vuln/SNYK-JS-WS-1296835) | **472/1000** **Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept
| Insecure Defaults [SNYK-JS-SOCKETIO-1024859](https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859) | **472/1000** **Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept
(*) Note that the real score may have changed since the PR was raised.
Release notes Package name: socket.io
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to upgrade socket.io from 2.2.0 to 2.5.0.
![merge advice](https://app.snyk.io/badges/merge-advice/?package_manager=npm&package_name=socket.io&from_version=2.2.0&to_version=2.5.0&pr_id=017efdd1-96b3-4d00-a4ad-940a2ed1d9ed&visibility=true&has_feature_flag=false) :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.- The recommended version is **4 versions** ahead of your current version. - The recommended version was released **3 months ago**, on 2022-06-26. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Access Restriction Bypass
[SNYK-JS-XMLHTTPREQUESTSSL-1255647](https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1255647) | **472/1000**
**Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept | Arbitrary Code Injection
[SNYK-JS-XMLHTTPREQUESTSSL-1082936](https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936) | **472/1000**
**Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept | Denial of Service (DoS)
[SNYK-JS-SOCKETIOPARSER-1056752](https://snyk.io/vuln/SNYK-JS-SOCKETIOPARSER-1056752) | **472/1000**
**Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-WS-1296835](https://snyk.io/vuln/SNYK-JS-WS-1296835) | **472/1000**
**Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept | Insecure Defaults
[SNYK-JS-SOCKETIO-1024859](https://snyk.io/vuln/SNYK-JS-SOCKETIO-1024859) | **472/1000**
**Why?** Proof of Concept exploit, CVSS 7.3 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: socket.io
The default value of the
maxHttpBufferSize
option has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.Security advisory: GHSA-j4f2-536g-r55m
Bug Fixes
Links:
~3.6.0
(diff)~7.4.2
Commit messages
Package name: socket.io
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
🧐 View latest project report
🛠 Adjust upgrade PR settings
🔕 Ignore this dependency or unsubscribe from future upgrade PRs