node.js realtime framework server
92%
Total Score
60
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2024-38355 socket.io is vulnerable to Improper Input Validation in versions 0.0.0 - 2.5.0 and 3.0.0 - 4.6.2. | 0.0.0 - 2.5.03.0.0 - 4.6.2 | High |
CVE-2020-28481 socket.io is vulnerable to Origin Validation Error in versions 0.0.0 - 2.4.0. | 0.0.0 - 2.4.0 | Medium |
CVE-2017-16031 socket.io is vulnerable to Use of Insufficiently Random Values in versions 0.0.0 - 0.9.6. | 0.0.0 - 0.9.6 | High |
| Dependency | Last Release | Score |
|---|---|---|
cors Version ~2.8.5 | — | — |
debug Version ~4.4.1 | — | — |
accepts Version ~1.3.4 | — | — |
base64id Version ~2.0.0 | — | — |
engine.io Version ~6.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant