Uh oh!
There was an error while loading. Please reload this page.
fix(deps): bump socket.io-parser to 4.2.6 to fix CVE-2026-33151 - #19880
Conversation
Fixes Dependabot alert #1223. Bumps socket.io-parser from 4.2.4 to 4.2.6 to address unbounded binary attachment memory exhaustion vulnerability. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Semver Impact of This PR🟢 Patch (bug fixes) 📋 Changelog PreviewThis is how your changes will appear in the changelog. New Features ✨
Bug Fixes 🐛Deps
Other
Internal Changes 🔧
🤖 This preview updates automatically when you update the PR. |
size-limit report 📦
|
node-overhead report 🧳Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
|
Fixes Dependabot alert #1223. Bumps socket.io-parser from 4.2.4 to 4.2.6 to address unbounded binary attachment memory exhaustion vulnerability.