Description
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
Remediation
References
https://blog.caller.xyz/socketio-engineio-dos/
https://github.com/bcaller/kill-engine-io
https://github.com/socketio/socket.io-parser/commit/dcb942d24db97162ad16a67c2a0cf30875342d55
Related Vulnerabilities
CVE-2023-29205 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-xwiki
CVE-2022-36898 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations
CVE-2022-25895 Vulnerability in npm package lite-dev-server
CVE-2020-11057 Vulnerability in maven package org.xwiki.platform:xwiki-platform-dashboard-macro
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk15on