Skip to content

[Component Vulnerability]please consider to upgrade ws in @microsoft/signalr from @^7.4.5 to @^7.5.10 #56723

Description

@tmbp95

Is there an existing issue for this?

  • I have searched the existing issues

Describe the bug

The @microsoft/signalr has ws@^7.4.5 as a dependency (here) that is vulnerable to Denial of Service (DoS) when the number of received headers exceed the server.maxHeadersCount or request.maxHeadersCount threshold.
snyk suggests that the affecting ws versions are >=2.1.0 <5.2.4 >=6.0.0 <6.2.3 >=7.0.0 <7.5.10 >=8.0.0 <8.17.1 (more info)

Expected Behavior

upgrade ws in @microsoft/signalr from @^7.4.5 to @^7.5.10 to solve this problem.

Steps To Reproduce

No response

Exceptions (if any)

No response

.NET Version

No response

Anything else?

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area-signalrIncludes: SignalR clients and servers

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions