SingalR 8.* version has vulnerable package ws 7.5.10
Open
area-signalr
- Dominant language
- C#
- Stars
- 38.4k
- Forks
- 10.9k
- Avg merge
- 2d 10h
- Merged PRs (30d)
- 281
Description
### Is there an existing issue for this?
- [x] I have searched the existing issues
### Describe the bug
Version of SignalR release 8 has reported vulnerable package ws 7.5.10
High - CVE-2026-48779
### Expected Behavior
_No response_
### Steps To Reproduce
_No response_
### Exceptions (if any)
_No response_
### .NET Version
_No response_
### Anything else?
_No response_
Contributor guide
Research direction
Start by locating the SignalR 8 release dependency that brings in ws 7.5.10 and check how the reported CVE is tracked in the repository. Confirm the completed change removes or updates that vulnerable package and verify the SignalR 8 dependency checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- csharp, javascript
- Domain
- backend-api-design, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100