Debian Patches

Status for node-socket.io-parser/4.2.4+~3.1.2-1

Patch Description Author Forwarded Bugs Origin Last update
CVE-2026-33151.patch Limit the number of binary attachments per packet (CVE-2026-33151) A specially crafted Socket.IO packet can make the server wait for a large
number of binary attachments and buffer them, which can be exploited to
make the server run out of memory. Add a configurable maxAttachments
option (default: 10) to the Decoder class.
no debian upstream, https://github.com/socketio/socket.io/commit/b25738c416c4e32fbff62ee182afa8f6d0dacf78

All known versions for source package 'node-socket.io-parser'

Links