engine.io vulnerabilities

The realtime engine behind Socket.IO. Provides the foundation of a bidirectional connection between client and server

  • latest version

    6.6.4

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    7 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the engine.io package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Uncaught Exception

    >=5.1.0 <6.4.2
    • H
    Denial of Service (DoS)

    <3.6.1>=4.0.0 <6.2.1
    • H
    Uncaught Exception

    >=4.0.0 <4.1.2>=5.0.0 <5.2.1>=6.0.0 <6.1.1
    • H
    Denial of Service (DoS)

    <3.6.0
    • M
    Denial of Service (DoS)

    <1.0.0

    Package versions

    154 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    6.6.428 Jan, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.323 Jan, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.29 Oct, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.121 Sep, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.6.021 Jun, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.5.518 Jun, 2024
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.5.49 Nov, 2023
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.5.36 Oct, 2023
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.5.22 Aug, 2023
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    6.5.2-alpha.11 Aug, 2023
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L