Source: node-socket.io-parser Version: 4.2.1+~3.1.0-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for node-socket.io-parser. CVE-2026-69185[0]: | Socket.IO enables bidirectional and low-latency communication for | every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially | crafted Socket.IO packet can make the server wait for a large number | of binary attachments and buffer them, which can be exploited to | make the server run out of memory. This vulnerability is fixed in | 4.2.7, 3.4.5, and 3.3.6. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-69185 https://www.cve.org/CVERecord?id=CVE-2026-69185 [1] https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr Please adjust the affected versions in the BTS as needed. Regards, Salvatore

