This repository was archived by the owner on Apr 3, 2026. It is now read-only.
fix(deps): update dependency socket.io to v4.6.2 [security]#399
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency socket.io to v4.6.2 [security]#399renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
2 times, most recently
from
March 11, 2025 11:20
2052e3b to
bfbe651
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
2 times, most recently
from
August 13, 2025 17:10
e4f11f4 to
4c9e710
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
August 19, 2025 19:31
4c9e710 to
c506309
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
August 31, 2025 13:51
c506309 to
b313f5f
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 25, 2025 21:39
b313f5f to
4eb6f59
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 21, 2025 23:54
4eb6f59 to
93bd5a2
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 10, 2025 15:09
93bd5a2 to
355c4fc
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 18, 2025 12:03
355c4fc to
ed56a0c
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
December 3, 2025 17:38
ed56a0c to
36634da
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
2 times, most recently
from
December 31, 2025 19:00
04b5875 to
825e09f
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
January 8, 2026 20:40
825e09f to
61cf793
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
January 19, 2026 14:49
61cf793 to
2cb02ac
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
February 2, 2026 21:46
2cb02ac to
2fbc54f
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
2 times, most recently
from
February 19, 2026 11:39
fb1d222 to
2de3d26
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
March 5, 2026 17:31
2de3d26 to
7df48ab
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
March 13, 2026 12:14
7df48ab to
f24b7ae
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
2 times, most recently
from
March 30, 2026 18:15
f24b7ae to
88e60fa
Compare
renovate
Bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 1, 2026 19:46
88e60fa to
b947643
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.5.3→4.6.24.5.1→4.6.2GitHub Vulnerability Alerts
CVE-2024-38355
Impact
A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.
Affected versions
4.6.2...latest3.0.0...4.6.1socket.io@4.6.2(at least)2.3.0...2.5.0socket.io@2.5.1Patches
This issue is fixed by socketio/socket.io@15af22f, included in
socket.io@4.6.2(released in May 2023).The fix was backported in the 2.x branch today: socketio/socket.io@d30630b
Workarounds
As a workaround for the affected versions of the
socket.iopackage, you can attach a listener for the "error" event:For more information
If you have any questions or comments about this advisory:
Thanks a lot to Paul Taylor for the responsible disclosure.
References
Release Notes
socketio/socket.io (socket.io)
v4.6.2Compare Source
Bug Fixes
typescondition to the top (#4698) (3d44aae)Links
engine.io@~6.4.2(diff)ws@~8.11.0(no change)v4.6.1Compare Source
Bug Fixes
Links
engine.io@~6.4.1(diff)ws@~8.11.0(no change)v4.6.0Compare Source
Bug Fixes
Features
Promise-based acknowledgements
This commit adds some syntactic sugar around acknowledgements:
emitWithAck()serverSideEmitWithAck()Added in 184f3cf.
Connection state recovery
This feature allows a client to reconnect after a temporary disconnection and restore its state:
Usage:
Here's how it works:
idattribute, which is public and can be freely shared)The in-memory adapter already supports this feature, and we will soon update the Postgres and MongoDB adapters. We will also create a new adapter based on Redis Streams, which will support this feature.
Added in 54d5ee0.
Compatibility (for real) with Express middlewares
This feature implements middlewares at the Engine.IO level, because Socket.IO middlewares are meant for namespace authorization and are not executed during a classic HTTP request/response cycle.
Syntax:
A workaround was possible by using the allowRequest option and the "headers" event, but this feels way cleaner and works with upgrade requests too.
Added in 24786e7.
Error details in the disconnecting and disconnect events
The
disconnectevent will now contain additional details about the disconnection reason.Added in 8aa9499.
Automatic removal of empty child namespaces
This commit adds a new option, "cleanupEmptyChildNamespaces". With this option enabled (disabled by default), when a socket disconnects from a dynamic namespace and if there are no other sockets connected to it then the namespace will be cleaned up and its adapter will be closed.
Added in 5d9220b.
A new "addTrailingSlash" option
The trailing slash which was added by default can now be disabled:
In the example above, the clients can omit the trailing slash and use
/socket.ioinstead of/socket.io/.Added in d0fd474.
Performance Improvements
Links:
engine.io@~6.4.0(diff)ws@~8.11.0(diff)v4.5.4Compare Source
This release contains a bump of:
engine.ioin order to fix CVE-2022-41940socket.io-parserin order to fix CVE-2022-2421.Links:
engine.io@~6.2.1(diff)ws@~8.2.3Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.