Junglewise Threat Intelligence

CVE-2023-32695: Socket.IO Parser insufficient input validation denial of service

CVE-2023-32695 · Severity: low · CVSS 3.1 · Published 2023-05-23

Executive brief

Socket.IO Parser is a JavaScript library that handles real-time bidirectional communication packets for Node.js applications. A malformed Socket.IO packet can cause an uncaught exception that crashes the entire Node.js process, resulting in service outage and potential data loss for connected clients.

Technical details

A specially crafted Socket.IO packet fails validation during decoding and triggers a TypeError ("Cannot convert object to primitive value") in the Socket.IO event emitter, causing an uncaught exception that terminates the Node.js process. The vulnerability exists in socket.io-parser versions 4.0.4–4.2.2, 3.4.0–3.4.2, and all earlier versions prior to 3.3.4. No authentication or special privileges are required; an attacker on the network can send a malicious packet directly to the server. Patches were released on 2023-05-22 in socket.io-parser 4.2.3, 3.4.3, and 3.3.4.

Affected products

  • Socket.IO socket.io-parser 4.0.4–4.2.2, 3.4.0–3.4.2, and prior versions before 3.3.4

Timeline

  • 2023-05-22: disclosed: Advisory published and patches released
  • 2023-05-22: patched: Fixes in socket.io-parser 4.2.3, 3.4.3, and 3.3.4

References