Medium severity5.3NVD Advisory· Published Jan 19, 2021· Updated Jun 17, 2026
CVE-2020-28481
CVE-2020-28481
Description
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
socket.ionpm | < 2.4.0 | 2.4.0 |
Affected products
3- socket.io/socket.iodescription
Patches
Vulnerability mechanics
References
7- github.com/socketio/socket.io/issues/3671nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-fxwf-4rqh-v8g3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28481ghsaADVISORY
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1056358nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1056357nvdThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-SOCKETIO-1024859nvdThird Party AdvisoryWEB
- github.com/socketio/socket.io/commit/f78a575f66ab693c3ea96ea88429ddb1a44c86c7ghsaWEB
News mentions
0No linked articles in our index yet.