In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade engine.io to version 6.6.10 or higher.
engine.io is a realtime engine behind Socket.IO. It provides the foundation of a bidirectional connection between client and server
Affected versions of this package are vulnerable to Uncaught Exception via the session upgrade handler in server.ts, where follow-up requests and transport upgrades do not validate that the Engine.IO protocol revision matches the one negotiated during the initial handshake. An attacker can send an upgrade request with a mismatched or missing EIO query parameter, causing a transport using a different parser and heartbeat mode to attach to an existing session, which disrupts the session and results in a crash.