Releases: socketio/socket.io
[email protected]
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736.
Note from the ws maintainers:
Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.
Bug Fixes
[email protected]
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736.
Note from the ws maintainers:
Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.
Bug Fixes
- clean up resources upon WebTransport handshake failure (f86b95f)
Dependencies
[email protected]
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736.
Note from the ws maintainers:
Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.
Dependencies
[email protected]
Bug Fixes
- close HTTP requests with invalid content type (fc11285)
- handle invalid packets when upgrading to WebTransport (1fa1f46)
- prevent WebTransport connections when a middleware is registered (d1f5aa9)
Dependencies
ws@~8.18.3(no change)
[email protected]
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
Bug Fixes
- add a limit to the number of binary attachments (b25738c)
[email protected]
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
Bug Fixes
- add a limit to the number of binary attachments (719f9eb)
[email protected]
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
Bug Fixes
- add a limit to the number of binary attachments (9d39f1f)
[email protected]
Bug Fixes
- add
@types/wsas dependency (#5458) (07cbe15) - uws: emit initial_headers and headers events in uServer (#5460) (44ed73f)
Dependencies
ws@~8.18.3(no change)
[email protected]
Bug Fixes
- do not throw when calling io.close() on a stopped server (9581f9b)
Dependencies
engine.io@~6.6.0(no change)ws@~8.18.3(no change)
[email protected]
This release contains a bump of debug from ~4.3.1 to ~4.4.1.