VYPR

deepstream.io

by DeepstreamIO

Source repositories

CVEs (2)

  • CVE-2026-49252CriJun 18, 2026
    risk 0.57cvss 9.9epss 0.00

    deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write…

  • CVE-2026-63116HigSep 21, 2026
    risk 0.50cvss 8.8epss 0.00

    deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When an authenticated user sends a PATCH_MULTI…