← Back

Sockjs Project

sockjs_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Sockjs
sockjs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sockjs Project
1Sockjs
Jun 17, 2026
Jul 9, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
1Sockjs Project
1Sockjs
Jun 17, 2026
Feb 10, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter.