#1143598 node-socket.io-parser: CVE-2026-69185

#1143598#5
Date:
2026-08-04 17:44:04 UTC
From:
To:
Hi,

The following vulnerability was published for node-socket.io-parser.

CVE-2026-69185[0]:
| Socket.IO enables bidirectional and low-latency communication for
| every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially
| crafted Socket.IO packet can make the server wait for a large number
| of binary attachments and buffer them, which can be exploited to
| make the server run out of memory. This vulnerability is fixed in
| 4.2.7, 3.4.5, and 3.3.6.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-69185
https://www.cve.org/CVERecord?id=CVE-2026-69185
[1] https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143598#8
Date:
2026-08-04 19:31:16 UTC
From:
To:
Hello,

Bug #1143598 in node-socket.io-parser reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-socket.io-parser/-/commit/98f3664db1ca2f062f42cb231f92154ad8c74947

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143598

#1143598#13
Date:
2026-08-04 19:31:15 UTC
From:
To:
Hello,

Bug #1143598 in node-socket.io-parser reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-socket.io-parser/-/commit/98f3664db1ca2f062f42cb231f92154ad8c74947

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143598

#1143598#18
Date:
2026-08-08 17:19:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-socket.io-parser, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143598@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-socket.io-parser package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 08 Aug 2026 18:58:35 +0200
Source: node-socket.io-parser
Architecture: source
Version: 4.2.4+~3.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1143598
Changes:
 node-socket.io-parser (4.2.4+~3.1.2-1) unstable; urgency=medium
 .
   * Team upload
   * Declare compliance with policy 4.7.4
   * New upstream version (Closes: #1143598, CVE-2026-69185)
   * Update patches
Checksums-Sha1:
 3763d94fcb5649d735c03b06d4867ce0fdd8a575 2767 node-socket.io-parser_4.2.4+~3.1.2-1.dsc
 41e5dc11f840574265f482b4dd7ba49016f8b451 9486 node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz
 e8e40bb06b210aaf170b4e9ff645d53c42226326 160474 node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz
 8497d8666e9d47f0af54f1e0fd6b82caaf26b093 4500 node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz
Checksums-Sha256:
 0757b060bd31ed97667adcc0cbbb19f0d9a7e62109ef0f72e61bdb03f623f9d3 2767 node-socket.io-parser_4.2.4+~3.1.2-1.dsc
 3cfe8fe44e9b47f5190feb2243f9d21aef4a0e17c3e77dc4eb438f218e2eaf3a 9486 node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz
 c8aa8646fc4f4218c0bef4e5694bbe545298dee8d15acc3de95285b45b338a6f 160474 node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz
 ca08612094cff36e0c84366c5200a8359ca55eae19b4c885c7aadd247bbd197e 4500 node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz
Files:
 59fc15c9526d2053f3e7e014379ebc50 2767 javascript optional node-socket.io-parser_4.2.4+~3.1.2-1.dsc
 6d2ce6abf95d7b3437ad8c00acc805e7 9486 javascript optional node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz
 740774c2eea8f1559ac37be1a5e7503f 160474 javascript optional node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz
 e15229956c6c1215685ef3a7e8f9aecb 4500 javascript optional node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmp3YMoACgkQ9tdMp8mZ
7un9JQ//YC/mNTtEIRtoA0vJb2ZgUPhfkw6cLr/XxknyghlOSPD5UWzvP+qNKVyr
Pnb39RK8Xqg48LLmMGfGDo3ZRbv3IgtgU55aWjvsbgopVQEs3menu7WaTDuEkYBX
cENxIupEn9sn9eaEoRcz5KDWUCpujtxkQ88CHqURjirn5L2IavzpBiYmib84bGHY
CwytHxXdDkGMscOtVWIZMv641QvqhMVncK9c+IlX2iBHjTeRkWfq60SkVwbvvWS6
X7AJp+EIh+x/pn9ojZxuR4F0N3Xu9YWhwk7C38JImD2Qg524VBEV4YBb3gRVRPvs
qFzFLPA8LyA++3h6BhWXr9wj983JtPD/lE6NmYAIy7HQGCEeadgEaXgwyXVpMx+h
4x90UAUhSzTYq4omAKF6z9gTJkdYikSMn0mHEkYyTpJ9pl2LTSRC+WrxhFQCXIw4
1JeauemE8Dwf63no2BZn6iFxkrYXVzYI/JB+yrMwok9veJvkoGtgiKJHNtRpM+rY
SyH/3NYZ4lTh+2cUU0t8zoo1G7j3dESzx3jff4PvXh8HN0fdWa7T9YSNFKDsDha5
LsNijctPbinic89bl2C+1wTmPXwf3h8HZ/qLs4DrhtIzaIHnDE+V4udn6xsPJXHh
yBdXXc2/Dduf6/M/7fwe8LfzCxYbrGlL/Sm5sxmF383Qzp3ehM0=
=n5Kl
-----END PGP SIGNATURE-----