Executive brief
Socket.IO Parser is a JavaScript library that handles real-time bidirectional communication packets for Node.js applications. A malformed Socket.IO packet can cause an uncaught exception that crashes the entire Node.js process, resulting in service outage and potential data loss for connected clients.
Technical details
A specially crafted Socket.IO packet fails validation during decoding and triggers a TypeError ("Cannot convert object to primitive value") in the Socket.IO event emitter, causing an uncaught exception that terminates the Node.js process. The vulnerability exists in socket.io-parser versions 4.0.4–4.2.2, 3.4.0–3.4.2, and all earlier versions prior to 3.3.4. No authentication or special privileges are required; an attacker on the network can send a malicious packet directly to the server. Patches were released on 2023-05-22 in socket.io-parser 4.2.3, 3.4.3, and 3.3.4.
Affected products
- Socket.IO socket.io-parser 4.0.4–4.2.2, 3.4.0–3.4.2, and prior versions before 3.3.4
Timeline
- 2023-05-22: disclosed: Advisory published and patches released
- 2023-05-22: patched: Fixes in socket.io-parser 4.2.3, 3.4.3, and 3.3.4