@deepstream/server
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @deepstream/serverpage 1 of 1
- CVE-2026-49252CRITICALCVSS 9.9EG 9.9fixed in 10.0.52026-06-18
deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation fr…
- CVE-2026-63116HIGHCVSS 8.8EG 8.8fixed in 10.1.12026-09-21
vulnerable: 10.1.0
deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When a…
Check whether @deepstream/server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @deepstream/server CVEs against the assets you own.
Book a Demo →