- Package:
- src:node-socket.io-parser
- Source:
- src:node-socket.io-parser
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-08 17:21:01 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-socket.io-parser. CVE-2026-69185[0]: | Socket.IO enables bidirectional and low-latency communication for | every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially | crafted Socket.IO packet can make the server wait for a large number | of binary attachments and buffer them, which can be exploited to | make the server run out of memory. This vulnerability is fixed in | 4.2.7, 3.4.5, and 3.3.6. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-69185 https://www.cve.org/CVERecord?id=CVE-2026-69185 [1] https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1143598 in node-socket.io-parser reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-socket.io-parser/-/commit/98f3664db1ca2f062f42cb231f92154ad8c74947 (this message was generated automatically) -- Greetings https://bugs.debian.org/1143598
Hello, Bug #1143598 in node-socket.io-parser reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-socket.io-parser/-/commit/98f3664db1ca2f062f42cb231f92154ad8c74947 (this message was generated automatically) -- Greetings https://bugs.debian.org/1143598
We believe that the bug you reported is fixed in the latest version of node-socket.io-parser, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1143598@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-socket.io-parser package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sat, 08 Aug 2026 18:58:35 +0200 Source: node-socket.io-parser Architecture: source Version: 4.2.4+~3.1.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1143598 Changes: node-socket.io-parser (4.2.4+~3.1.2-1) unstable; urgency=medium . * Team upload * Declare compliance with policy 4.7.4 * New upstream version (Closes: #1143598, CVE-2026-69185) * Update patches Checksums-Sha1: 3763d94fcb5649d735c03b06d4867ce0fdd8a575 2767 node-socket.io-parser_4.2.4+~3.1.2-1.dsc 41e5dc11f840574265f482b4dd7ba49016f8b451 9486 node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz e8e40bb06b210aaf170b4e9ff645d53c42226326 160474 node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz 8497d8666e9d47f0af54f1e0fd6b82caaf26b093 4500 node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz Checksums-Sha256: 0757b060bd31ed97667adcc0cbbb19f0d9a7e62109ef0f72e61bdb03f623f9d3 2767 node-socket.io-parser_4.2.4+~3.1.2-1.dsc 3cfe8fe44e9b47f5190feb2243f9d21aef4a0e17c3e77dc4eb438f218e2eaf3a 9486 node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz c8aa8646fc4f4218c0bef4e5694bbe545298dee8d15acc3de95285b45b338a6f 160474 node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz ca08612094cff36e0c84366c5200a8359ca55eae19b4c885c7aadd247bbd197e 4500 node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz Files: 59fc15c9526d2053f3e7e014379ebc50 2767 javascript optional node-socket.io-parser_4.2.4+~3.1.2-1.dsc 6d2ce6abf95d7b3437ad8c00acc805e7 9486 javascript optional node-socket.io-parser_4.2.4+~3.1.2.orig-socket-io-component-emitter.tar.gz 740774c2eea8f1559ac37be1a5e7503f 160474 javascript optional node-socket.io-parser_4.2.4+~3.1.2.orig.tar.gz e15229956c6c1215685ef3a7e8f9aecb 4500 javascript optional node-socket.io-parser_4.2.4+~3.1.2-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmp3YMoACgkQ9tdMp8mZ 7un9JQ//YC/mNTtEIRtoA0vJb2ZgUPhfkw6cLr/XxknyghlOSPD5UWzvP+qNKVyr Pnb39RK8Xqg48LLmMGfGDo3ZRbv3IgtgU55aWjvsbgopVQEs3menu7WaTDuEkYBX cENxIupEn9sn9eaEoRcz5KDWUCpujtxkQ88CHqURjirn5L2IavzpBiYmib84bGHY CwytHxXdDkGMscOtVWIZMv641QvqhMVncK9c+IlX2iBHjTeRkWfq60SkVwbvvWS6 X7AJp+EIh+x/pn9ojZxuR4F0N3Xu9YWhwk7C38JImD2Qg524VBEV4YBb3gRVRPvs qFzFLPA8LyA++3h6BhWXr9wj983JtPD/lE6NmYAIy7HQGCEeadgEaXgwyXVpMx+h 4x90UAUhSzTYq4omAKF6z9gTJkdYikSMn0mHEkYyTpJ9pl2LTSRC+WrxhFQCXIw4 1JeauemE8Dwf63no2BZn6iFxkrYXVzYI/JB+yrMwok9veJvkoGtgiKJHNtRpM+rY SyH/3NYZ4lTh+2cUU0t8zoo1G7j3dESzx3jff4PvXh8HN0fdWa7T9YSNFKDsDha5 LsNijctPbinic89bl2C+1wTmPXwf3h8HZ/qLs4DrhtIzaIHnDE+V4udn6xsPJXHh yBdXXc2/Dduf6/M/7fwe8LfzCxYbrGlL/Sm5sxmF383Qzp3ehM0= =n5Kl -----END PGP SIGNATURE-----