NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1776 most downloaded on npm
socket.io protocol parser
Last release 2 months ago
16 Jul 2026
Release timing varies
gaps range from 9 days to 1.4 years
Most releases are documented
notes for 36 of 58 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
61 releases · first in 2012
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
One column per quarter.
This release contains a bump of debug from ~4.3.1 to ~4.4.1.
This release contains a bump of debug from ~4.3.1 to ~4.4.1.
ensure reserved events cannot be used as event names
check the format of the event name
calling destroy() should clear all internal state
check the format of the index of each attachment
typings: allow async listener in typed events
typings: ensure compatibility with TypeScript 3.x
typings: properly type server-side events
Blog post: https://socket.io/blog/socket-io-4-1-0/
Blog post: https://socket.io/blog/socket-io-4-1-0/
engine.io)engine.io)~5.1.0~7.4.2check the format of the index of each attachment
### Bug Fixes * allow integers as event names
Nothing published for this version
typings: make "engine" attribute public
typings: add fallback to untyped event listener
Nothing published for this version
move binary detection back to the parser
add support for a payload in a CONNECT packet
Blog post: https://socket.io/blog/socket-io-4-release/ Migration guide: https://socket.io/docs/v3/migrating-from-3-x-to-4-0/
Blog post: https://socket.io/blog/socket-io-4-release/ Migration guide: https://socket.io/docs/v3/migrating-from-3-x-to-4-0/
io.to(...) now returns an immutable operatorPreviously, broadcasting to a given room (by calling io.to()) would mutate the io instance, which could lead to surprising behaviors, like:
io.to("room1");
io.to("room2").emit(/* ... */); // also sent to room1
// or with async/await
io.to("room3").emit("details", await fetchDetails()); // random behavior: maybe in room3, maybe to all clients
Calling io.to() (or any other broadcast modifier) will now return an immutable instance.
~5.0.0~7.4.2This release will be included in Socket.IO v3.
There is a breaking API change (see below), but the exchange protocol is left untouched and thus stays in version 4.
reject binary packets with zero attachments
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
check the format of the event name
check the format of the index of each attachment
prevent DoS (OOM) via massive packets
Nothing published for this version
reject binary packets with zero attachments
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.
check the format of the event name
check the format of the index of each attachment
prevent DoS (OOM) via massive packets
Nothing published for this version
remove any reference to the global variable
global variable (b47efb2)Nothing published for this version
Nothing published for this version
ignore packets received after disconnection
properly parse the CONNECT packet in v2 compatibility mode
~4.1.0~7.4.2In order to ease the migration to Socket.IO v3, the v3 server is now able to communicate with v2 clients:
In order to ease the migration to Socket.IO v3, the v3 server is now able to communicate with v2 clients:
const io = require("socket.io")({
allowEIO3: true // false by default
});
Note: the allowEIO3 refers to the version 3 of the Engine.IO protocol which is used in Socket.IO v2
~4.1.0~7.4.2More details about this release in the blog post: https://socket.io/blog/socket-io-3-release/
More details about this release in the blog post: https://socket.io/blog/socket-io-3-release/
Dedicated migration guide: https://socket.io/docs/migrating-from-2-x-to-3-0/
the Socket#use() method is removed (see 5c73733)
Socket#join() and Socket#leave() do not accept a callback argument anymore.
Before:
socket.join("room1", () => {
io.to("room1").emit("hello");
});
After:
socket.join("room1");
io.to("room1").emit("hello");
// or await socket.join("room1"); for custom adapters
Before:
new Server(3000, {
origins: ["https://example.com"]
});
The 'origins' option was used in the allowRequest method, in order to determine whether the request should pass or not. And the Engine.IO server would implicitly add the necessary Access-Control-Allow-xxx headers.
After:
new Server(3000, {
cors: {
origin: "https://example.com",
methods: ["GET", "POST"],
allowedHeaders: ["content-type"]
}
});
The already existing 'allowRequest' option can be used for validation:
new Server(3000, {
allowRequest: (req, callback) => {
callback(null, req.headers.referer.startsWith("https://example.com"));
}
});
Socket#rooms is now a Set instead of an object
Namespace#connected is now a Map instead of an object
there is no more implicit connection to the default namespace:
// client-side
const socket = io("/admin");
// server-side
io.on("connect", socket => {
// not triggered anymore
})
io.use((socket, next) => {
// not triggered anymore
});
io.of("/admin").use((socket, next) => {
// triggered
});
This method was kept for backward-compatibility with pre-1.0 versions.
~4.0.0^7.1.2Nothing published for this version
Nothing published for this version
This release mainly contains a bump of the engine.io and ws packages, but no additional features.
This release mainly contains a bump of the engine.io and ws packages, but no additional features.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
add cache-control header when serving the client source
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
add local flag to the socket object
socket.local.to('room101').emit(/* */);
(client) fire an error event on middleware failure for non-root namespace (https://github.com/socketio/socket.io-client/pull/1202)
There are two non-breaking changes that are somehow quite important:
// by default, the object is recursively scanned to check whether it contains some binary data
// in the following example, the check is skipped in order to improve performance
socket.binary(false).emit('plain-object', object);
// it also works at the namespace level
io.binary(false).emit('plain-object', object);
io.of(/^\/dynamic-\d+$/).on('connect', (socket) => {
// socket.nsp.name = '/dynamic-101'
});
// client-side
const client = require('socket.io-client')('/dynamic-101');
There are two non-breaking changes that are somehow quite important:
ws was reverted as the default wsEngine (https://github.com/socketio/engine.io/pull/550), as there was several blocking issues with uws. You can still use uws by running npm install uws --save in your project and using the wsEngine option:var engine = require('engine.io');
var server = engine.listen(3000, {
wsEngine: 'uws'
});
pingTimeout now defaults to 5 seconds (instead of 60 seconds): https://github.com/socketio/engine.io/pull/551a breaking change related to utf-8 encoding in engine.io-parser
This major release brings several performance improvements:
uws is now the default Websocket engine. It should bring significant improvement in performance (particularly in terms of memory consumption) (https://github.com/socketio/engine.io/releases/tag/2.0.0)
the Engine.IO and Socket.IO handshake packets were merged, reducing the number of roundtrips necessary to establish a connection. (#2833)
it is now possible to provide a custom parser according to the needs of your application (#2829). Please take a look at the example for more information.
Please note that this release is not backward-compatible, due to:
Please also note that if you are using a self-signed certificate, rejectUnauthorized now defaults to true (https://github.com/socketio/engine.io-client/pull/558).
Finally, the API documentation is now in the repository (here), and the content of the website here. Do not hesitate if you see something wrong or missing!
The full list of changes:
local flag (#2816)clients method in the API documentation (#2812)Besides, we are proud to announce that Socket.IO is now a part of open collective: https://opencollective.com/socketio. More on that later.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →