Vulnerability Details CVE-2023-32695
socket.io parser is a socket.io encoder and decoder written in JavaScript complying with version 5 of socket.io-protocol. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. A patch has been released in version 4.2.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.9%
CVSS Severity
CVSS v3 Score 7.3
Products affected by CVE-2023-32695
-
cpe:2.3:a:socket:socket.io-parser:3.4.0
-
cpe:2.3:a:socket:socket.io-parser:3.4.1
-
cpe:2.3:a:socket:socket.io-parser:3.4.2
-
cpe:2.3:a:socket:socket.io-parser:4.0.4
-
cpe:2.3:a:socket:socket.io-parser:4.0.5
-
cpe:2.3:a:socket:socket.io-parser:4.1.0
-
cpe:2.3:a:socket:socket.io-parser:4.1.1
-
cpe:2.3:a:socket:socket.io-parser:4.1.2
-
cpe:2.3:a:socket:socket.io-parser:4.2.0
-
cpe:2.3:a:socket:socket.io-parser:4.2.1
-
cpe:2.3:a:socket:socket.io-parser:4.2.2