NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2420 most downloaded on npm
Client for the realtime Engine
Last release 9 days ago
25 Sep 2026
Release timing varies
gaps range from 4 weeks to 10 months
Most releases are documented
notes for 38 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
166 releases · first in 2012
types: export reserved event interfaces
ws@~8.21.0 (no change)The ws dependency was bumped to ~8.21.0 following CVE-2026-48779 .
One column per quarter.
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736 .
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736.
Note from the ws maintainers:
Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.
This release contains a bump of:
This release contains a bump of:
ws from ~8.17.1 to ~8.18.3debug from ~4.3.1 to ~4.4.1correctly consume the ws package
types: remove ws type from .d.ts file
ws@~8.17.1 (no change)move 'offline' event listener at the top
ws@~8.17.1 (no change)The transports option now accepts an array of transport implementations:
The transports option now accepts an array of transport implementations:
import { Socket, XHR, WebSocket } from "engine.io-client";
const socket = new Socket({
transports: [XHR, WebSocket]
});
Here is the list of provided implementations:
| Transport | Description |
|---|---|
Fetch |
HTTP long-polling based on the built-in fetch() method. |
NodeXHR |
HTTP long-polling based on the XMLHttpRequest object provided by the xmlhttprequest-ssl package. |
XHR |
HTTP long-polling based on the built-in XMLHttpRequest object. |
NodeWebSocket |
WebSocket transport based on the WebSocket object provided by the ws package. |
WebSocket |
WebSocket transport based on the built-in WebSocket object. |
WebTransport |
WebTransport transport based on the built-in WebTransport object. |
Usage:
| Transport | browser | Node.js | Deno | Bun |
|---|---|---|---|---|
Fetch |
:white_check_mark: | :white_check_mark: (1) | :white_check_mark: | :white_check_mark: |
NodeXHR |
:white_check_mark: | :white_check_mark: | :white_check_mark: | |
XHR |
:white_check_mark: | |||
NodeWebSocket |
:white_check_mark: | :white_check_mark: | :white_check_mark: | |
WebSocket |
:white_check_mark: | :white_check_mark: (2) | :white_check_mark: | :white_check_mark: |
WebTransport |
:white_check_mark: | :white_check_mark: |
(1) since v18.0.0 (2) since v21.0.0
The feature above also comes with the ability to exclude the code related to unused transports (a.k.a. "tree-shaking"):
import { SocketWithoutUpgrade, WebSocket } from "engine.io-client";
const socket = new SocketWithoutUpgrade({
transports: [WebSocket]
});
In that case, the code related to HTTP long-polling and WebTransport will be excluded from the final bundle.
Added in f4d898e
When setting the tryAllTransports option to true, if the first transport (usually, HTTP long-polling) fails, then the other transports will be tested too:
import { Socket } from "engine.io-client";
const socket = new Socket({
tryAllTransports: true
});
This feature is useful in two cases:
transports: ["websocket", "polling"])The only potential downside is that the connection attempt could take more time in case of failure, as there have been reports of WebSocket connection errors taking several seconds before being detected (that's one reason for using HTTP long-polling first). That's why the option defaults to false for now.
Added in 579b243.
ws@~8.17.1 (no change)This release contains a bump of the ws dependency, which includes an important security fix.
This release contains a bump of the ws dependency, which includes an important security fix.
Advisory: https://github.com/advisories/GHSA-3h5v-q93c-6h6q
add a maximum length for the URL
ws@~8.11.0 (no change)webtransport: add proper framing
make closeOnBeforeunload default to false
ws@~8.11.0 (no change)The Engine.IO client can now use WebTransport as the underlying transport.
The Engine.IO client can now use WebTransport as the underlying transport.
WebTransport is a web API that uses the HTTP/3 protocol as a bidirectional transport. It's intended for two-way communications between a web client and an HTTP/3 server.
References:
For Node.js clients: until WebTransport support lands in Node.js, you can use the @fails-components/webtransport package:
import { WebTransport } from "@fails-components/webtransport";
global.WebTransport = WebTransport;
Added in 7195c0f.
When setting the withCredentials option to true, the Node.js client will now include the cookies in the HTTP requests, making it easier to use it with cookie-based sticky sessions.
import { Socket } from "engine.io-client";
const socket = new Socket("https://example.com", {
withCredentials: true
});
Added in 5fc88a6.
ws@~8.11.0 (no change)The minor bump is due to changes on the server side.
typings: do not expose browser-specific types
ws@~8.11.0 (no change)properly parse relative URL with a "@" character
The trailing slash which was added by default can now be disabled:
import { Socket } from "engine.io-client";
const socket = new Socket("https://example.com", {
addTrailingSlash: false
});
In the example above, the request URL will be https://example.com/engine.io instead of https://example.com/engine.io/.
properly clear "beforeunload" event listener
This check was added for the flashsocket transport, which has been deprecated for a while now ([1]). But it fails with latest webpack versions, as the…
This check was added for the flashsocket transport, which has been deprecated for a while now ([1]). But it fails with latest webpack versions, as the expression "__initialize" in WebSocket gets evaluated to true.
Default export of globalThis seems to have a problem in the "browser" field when the library is loaded asynchronously with webpack.
add details to the "close" event
The close event will now include additional details to help debugging if anything has gone wrong.
Example when a payload is over the maxHttpBufferSize value in HTTP long-polling mode:
socket.on("close", (reason, details) => {
console.log(reason); // "transport error"
// in that case, details is an error object
console.log(details.message); "xhr post error"
console.log(details.description); // 413 (the HTTP status of the response)
// details.context refers to the XMLHttpRequest object
console.log(details.context.status); // 413
console.log(details.context.responseText); // ""
});
Note: the error object was already included before this commit and is kept for backward compatibility.
The server will now include a "maxPayload" field in the handshake details, allowing the clients to decide how many packets they have to send to stay under the maxHttpBufferSize value.
Nothing published for this version
add package name in nested package.json
Nothing published for this version
Some bug fixes were backported from master, to be included by the latest socket.io-client version.
### Bug Fixes * bundle: fix vite build
This major release contains three important changes:
This major release contains three important changes:
There is now three distinct builds (in the build/ directory):
And three bundles (in the dist/ directory) :
engine.io.js: unminified UMD bundleengine.io.min.js: minified UMD bundleengine.io.esm.min.js: ESM bundlePlease note that the communication protocol was not updated, so a v5 client will be able to reach a v6 server (and vice-versa).
Reference: https://github.com/socketio/engine.io-protocol
ws version: ~8.2.3
Nothing published for this version
Nothing published for this version
emit ping when receiving a ping from the server
### Bug Fixes * fix JSONP transport on IE9
Nothing published for this version
The major bump is due to a breaking change on the server side.
Nothing published for this version
This release only contains a bump of xmlhttprequest-ssl, in order to fix the following vulnerability: https://www.npmjs.com/advisories/1665.
This release only contains a bump of xmlhttprequest-ssl, in order to fix the following vulnerability: https://www.npmjs.com/advisories/1665.
Please note that engine.io-client was not directly impacted by this vulnerability, since we are always using async: true.
Nothing published for this version
silently close the transport in the beforeunload hook
remove polyfill for process in the bundle
Nothing published for this version
check the type of the initial packet
Nothing published for this version
check the type of the initial packet
react-native: add a default value for the withCredentials option
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This release contains a bump of the ws dependency, which includes an important security fix.
This release contains a bump of the ws dependency, which includes an important security fix.
Advisory: https://github.com/advisories/GHSA-3h5v-q93c-6h6q
### Bug Fixes * fix usage with vite (280de36) ### Dependencies - `ws@~7.4.2` (no change)
This release only contains a bump of xmlhttprequest-ssl, in order to fix the following vulnerability: https://www.npmjs.com/advisories/1665.
This release only contains a bump of xmlhttprequest-ssl, in order to fix the following vulnerability: https://www.npmjs.com/advisories/1665.
Please note that engine.io-client was not directly impacted by this vulnerability, since we are always using async: true.
replace default nulls in SSL options with undefineds
Nothing published for this version
More details about this release in the blog post: https://socket.io/blog/engine-io-4-release/
More details about this release in the blog post: https://socket.io/blog/engine-io-4-release/
Nothing published for this version
Nothing published for this version
use globalThis polyfill instead of self/global
v3.x clients will not be able to connect anymore (they will send a ping packet and timeout while waiting for a pong packet).
the output bundle will now be found in the dist/ folder.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →