github socketio/engine.io 3.6.0

latest releases: 6.6.0, 3.6.2, 6.5.5...
2 years ago

Bug Fixes

  • add extension in the package.json main entry (#608) (3ad0567)
  • do not reset the ping timer after upgrade (1f5d469)

Features

  • decrease the default value of maxHttpBufferSize (58e274c)

This change reduces the default value from 100 mb to a more sane 1 mb.

This helps protect the server against denial of service attacks by malicious clients sending huge amounts of data.

See also: GHSA-j4f2-536g-r55m

  • increase the default value of pingTimeout (f55a79a)

Links

Don't miss a new engine.io release

NewReleases is sending notifications on new releases.