nats.ws@1.0.0-108 vulnerabilities

WebSocket NATS client

Direct Vulnerabilities

Known vulnerabilities in the nats.ws package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure

nats.ws is a WebSocket NATS client

Affected versions of this package are vulnerable to Information Exposure. NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

How to fix Information Exposure?

Upgrade nats.ws to version 1.0.0-111 or higher.

<1.0.0-111