The realtime engine behind Socket.IO. Provides the foundation of a bidirectional connection between client and server
92%
Total Score
61
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2023-31125 engine.io is vulnerable to Uncaught Exception in versions 5.1.0 - 6.4.2. | 5.1.0 - 6.4.2 | Medium |
CVE-2022-41940 engine.io is vulnerable to Uncaught Exception in versions 0.0.0 - 3.6.1 and 4.0.0 - 6.2.1. | 0.0.0 - 3.6.14.0.0 - 6.2.1 | Medium |
CVE-2020-36048 engine.io is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 3.6.0. | 0.0.0 - 3.6.0 | High |
CVE-2022-21676 engine.io is vulnerable to Improper Check for Unusual or Exceptional Conditions in versions 4.0.0 - 4.1.2, 5.0.0 - 5.2.1 and 6.0.0 - 6.1.1. | 4.0.0 - 4.1.25.0.0 - 5.2.16.0.0 - 6.1.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
ws Version ~8.20.1 | — | — |
cors Version ~2.8.5 | — | — |
debug Version ~4.4.1 | — | — |
cookie Version ~0.7.2 | — | — |
accepts Version ~1.3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant