Skip to content

chore: upgrade socket.io-parser to ^4.2.7 to address CVE-2026-69185 - #1542

Merged
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/socket.io-parser
Aug 5, 2026
Merged

chore: upgrade socket.io-parser to ^4.2.7 to address CVE-2026-69185#1542
brendan-kellam merged 3 commits into
mainfrom
cursor/cve/socket.io-parser

Conversation

@claude

@claude claude Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1819

Refreshes the socket.io-parser lockfile entry from 4.2.6 to 4.2.7, which addresses:

  • CVE-2026-69185 (HIGH) — Socket.IO zero-attachment memory exhaustion. A crafted Socket.IO packet can make the server wait for and buffer a large number of binary attachments, which can be used to exhaust server memory. Patched in 4.2.7 for the >=4.0.0 <4.2.7 range used by socket.io@4.x.

socket.io-parser is a transitive dependency (socket.io@4.8.1 via ~4.2.4). The existing range already admitted the patched version, so this is a lockfile refresh (yarn up -R socket.io-parser) with no package.json change and no resolutions override.

Verification

  • yarn why socket.io-parser reports 4.2.7 for the single requester; no 4.2.6 remains in the graph.
  • yarn build:deps succeeds.
  • yarn test passes (1760 tests across queryLanguage, shared, backend, web).

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency bump with no application code changes; risk is limited to parser behavior in the existing Socket.IO stack (e.g. react-email preview tooling).

Overview
Bumps the transitive socket.io-parser dependency from 4.2.6 to 4.2.7 via a yarn.lock refresh only—no package.json or resolutions changes. socket.io@4.8.1 already requests ~4.2.4, so this pins the patched release in the lockfile.

The upgrade addresses CVE-2026-69185: crafted Socket.IO packets with zero attachments could drive the server to buffer many binary attachments and exhaust memory.

The unreleased CHANGELOG entry records the security fix under Fixed.

Reviewed by Cursor Bugbot for commit a230768. Bugbot is set up for automated code reviews on this repo. Configure here.

claude Bot and others added 2 commits August 5, 2026 02:18
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

This comment has been minimized.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2196
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.2 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.2 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.3 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.12 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/codemirror-lang-elixir LICENSE = Apache License 2.0); npm registry manifest for 4.0.0 has no license field
khroma 2.1.0 UNKNOWN MIT GitHub repo (fabiospampinato/khroma license file = MIT License); npm registry manifest for 2.1.0 has no license field
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (livebook-dev/lezer-elixir LICENSE = Apache License 2.0); npm registry manifest for 1.1.2 has no license field
map-stream 0.1.0 UNKNOWN MIT GitHub repo (dominictarr/map-stream LICENCE = MIT License); npm registry manifest for 0.1.0 has no license field
memorystream 0.3.1 UNKNOWN MIT extracted from object (npm registry manifest legacy "licenses" field: [{"type":"MIT","url":"..."}]); confirmed by GitHub repo LICENSE (MIT)
pause-stream 0.0.11 ["MIT","Apache2"] MIT OR Apache-2.0 extracted from object (package.json license array ["MIT","Apache2"]); confirmed by GitHub repo LICENSE ("Dual Licensed MIT and Apache 2"), normalized "Apache2" to SPDX Apache-2.0
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 GitHub repo (PostHog/posthog-js LICENSE = Apache License 2.0); confirmed against installed 1.369.0 LICENSE file
valid-url 1.0.9 UNKNOWN MIT GitHub repo (ogt/valid-url LICENSE: "This software is released under the MIT license")

@brendan-kellam
brendan-kellam merged commit 80fc649 into main Aug 5, 2026
11 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/socket.io-parser branch August 5, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant