SockJS Project maintains a focused WebSocket polyfill library that abstracts transport protocols for real-time browser-server communication and is embedded in applications across the web platform stack. Vulnerabilities affecting the library center on exception-handling and cross-site scripting weaknesses that arise from its role as a message-transport intermediary between untrusted clients and server logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sockjs Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8823MEDIUM htmlfile in lib/transport/htmlfile.js in SockJS before 0.3.0 is vulnerable to Reflected XSS via the /htmlfile c (aka callback) parameter. | Feb 10, 2020 | 6.1 | 21 | NO | NO |
CVE-2020-7693MEDIUM Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20. | Jul 9, 2020 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sockjs Project.
Media articles that mention a CVE ID that affects a product developed by Sockjs Project — matched by CVE ID, not by vendor name.