socket.io-parser@3.3.5
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
- add a limit to the number of binary attachments (9d39f1f)
socket.io-parser@3.4.4
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
- add a limit to the number of binary attachments (719f9eb)
socket.io-parser@4.2.6
- add a limit to the number of binary attachments (b25738c)
engine.io@6.6.6
- add
@types/wsas dependency (#5458) (07cbe15) - uws emit initial_headers and headers events in uServer (#5460) (44ed73f)
ws@~8.18.3(no change)
socket.io@4.8.3
- do not throw when calling io.close() on a stopped server (9581f9b)
engine.io@~6.6.0(no change)ws@~8.18.3(no change)
socket.io-client@4.8.3
There were some minor bug fixes on the server side, which mandate a client bump.
engine.io-client@~6.6.1(no change)ws@~8.18.3(diff)
socket.io-parser@4.2.5
This release contains a bump of debug from ~4.3.1 to ~4.4.1.
socket.io-adapter@2.5.6
This release contains a bump of:
-
wsfrom~8.17.1to~8.18.3 -
debugfrom~4.3.1to~4.4.1
engine.io-client@6.6.4
This release contains a bump of:
wsfrom~8.17.1to~8.18.3debugfrom~4.3.1to~4.4.1
socket.io@4.8.2
The url.parse() function is now deprecated and has been replaced by new URL() (see 8af7019).
- call adapter.init() when creating each namespace (f3e1f5e)
- improve
io.close()function (#5344) (bb0b480)
engine.io@~6.6.0(no change)ws@~8.18.3(diff)