CVE-2022-2421: Socket.io - Improper type validation in attachment parsing

Published Oct 25, 2022
·
Updated

Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.

Other sources

Due to improper type validation in the socket.io-parser library (which is used by the socket.io and socket.io-client packages to encode and decode Socket.IO packets), it is possible to overwrite the placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.

Example:

js const decoder = new Decoder();

decoder.on("decoded", (packet) => { console.log(packet.data); // prints [ 'hello', [Function: splice] ] })

decoder.add('51-["hello",{"placeholder":true,"num":"splice"}]'); decoder.add(Buffer.from("world"));

This bubbles up in the socket.io package:

js io.on("connection", (socket) => { socket.on("hello", (val) => { // here, "val" could be a function instead of a buffer }); });

:warning: IMPORTANT NOTE :warning:

You need to make sure that the payload that you received from the client is actually a Buffer object:

js io.on("connection", (socket) => { socket.on("hello", (val) => { if (!Buffer.isBuffer(val)) { socket.disconnect(); return; } // ... }); });

If that's already the case, then you are not impacted by this issue, and there is no way an attacker could make your server crash (or escalate privileges, ...).

Example of values that could be sent by a malicious user:

- a number that is out of bounds

Sample packet: 451-["hello",{"placeholder":true,"num":10}]

js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is undefined }); });

- a value that is not a number, like undefined

Sample packet: 451-["hello",{"placeholder":true,"num":undefined}]

js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is undefined }); });

- a string that is part of the prototype of Array, like "push"

Sample packet: 451-["hello",{"placeholder":true,"num":"push"}]

js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is a reference to the "push" function }); });

- a string that is part of the prototype of Object, like "hasOwnProperty"

Sample packet: 451-["hello",{"placeholder":true,"num":"hasOwnProperty"}]

js io.on("connection", (socket) => { socket.on("hello", (val) => { // val is a reference to the "hasOwnProperty" function }); });

This should be fixed by:

- https://github.com/socketio/socket.io-parser/commit/b5d0cb7dc56a0601a09b056beaeeb0e43b160050, included in socket.io-parser@4.2.1 - https://github.com/socketio/socket.io-parser/commit/b559f050ee02bd90bd853b9823f8de7fa94a80d4, included in socket.io-parser@4.0.5 - https://github.com/socketio/socket.io-parser/commit/04d23cecafe1b859fb03e0cbf6ba3b74dff56d14, included in socket.io-parser@3.4.2 - https://github.com/socketio/socket.io-parser/commit/fb21e422fc193b34347395a33e0f625bebc09983, included in socket.io-parser@3.3.3

Dependency analysis for the socket.io package

| socket.io version | socket.io-parser version | Covered? | |---------------------|---------------------------------------------------------------------------------------------------------|------------------------| | 4.5.2...latest | ~4.2.0 (ref) | Yes :heavycheckmark: | | 4.1.3...4.5.1 | ~4.0.4 (ref) | Yes :heavycheckmark: | | 3.0.5...4.1.2 | ~4.0.3 (ref) | Yes :heavycheckmark: | | 3.0.0...3.0.4 | ~4.0.1 (ref) | Yes :heavycheckmark: | | 2.3.0...2.5.0 | ~3.4.0 (ref) | Yes :heavycheckmark: |

Dependency analysis for the socket.io-client package

| socket.io-client version | socket.io-parser version | Covered? | |----------------------------|----------------------------------------------------------------------------------------------------------------|------------------------------------| | 4.5.0...latest | ~4.2.0 (ref) | Yes :heavycheckmark: | | 4.3.0...4.4.1 | ~4.1.1 (ref) | No, but the impact is very limited | | 3.1.0...4.2.0 | ~4.0.4 (ref) | Yes :heavycheckmark: | | 3.0.5 | ~4.0.3 (ref) | Yes :heavycheckmark: | | 3.0.0...3.0.4 | ~4.0.1 (ref) | Yes :heavycheckmark: | | 2.2.0...2.5.0 | ~3.3.0 (ref) | Yes :heavycheckmark: |

GitHub

Affected Software

9 affected componentsFixes available
npm/socket.io-parser>=3.4.0<3.4.2
3.4.2
npm/socket.io-parser<3.3.3
3.3.3
npm/socket.io-parser>=4.0.0<4.0.5
4.0.5
npm/socket.io-parser>=4.1.0<4.2.1
4.2.1
Socket Socket.io-parser Node.js<4.0.5
Socket Socket.io-parser Node.js>=4.1.0<4.2.1
Socket Socket.io-parser Node.js<3.3.3
Socket Socket.io-parser Node.js>=3.4.0<3.4.2
Socket Socket.io-parser Node.js>=4.0.0<4.0.5

Event History

Oct 25, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
DescriptionSeverityWeakness
Oct 26, 2022
Advisory Published
12:00 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-2421?

CVE-2022-2421 is a vulnerability in the Socket.io js library that allows an attacker to overwrite the _placeholder object, potentially placing references to functions in the resulting query object.

2

What is the severity of CVE-2022-2421?

The severity of CVE-2022-2421 is critical with a severity value of 9.8.

3

Which software is affected by CVE-2022-2421?

The Socket.io-parser library versions 4.0.5 and 4.1.0 to 4.2.1 running on Node.js are affected by CVE-2022-2421.

4

How can an attacker exploit CVE-2022-2421?

An attacker can exploit CVE-2022-2421 by leveraging the improper type validation in attachment parsing to overwrite the _placeholder object and place references to functions in the resulting query object.

5

Is there a fix available for CVE-2022-2421?

Yes, it is recommended to update to a version of the Socket.io-parser library that is not affected by CVE-2022-2421.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203