CVE-2022-25867

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

Full-featured Socket.IO Client Library for Java, which is compatible with Socket.IO v1.0 and later.
GitHubGitHub
5.41K