{"id":"CVE-2026-64785","aliases":["GHSA-q3g2-m552-3r9c"],"title":"swift-nio-http2: Missing CR/LF/NUL validation in header values","summary":"swift-nio-http2: Missing CR/LF/NUL validation in header values","severity":"medium","cvss":5.3,"cwe":["CWE-113","CWE-444"],"vendor":"swift-nio-http2","product":"swift-nio-http2","ecosystem":"swift","affected":["swift-nio-http2 < 1.45.0"],"patched":["swift-nio-http2 1.45.0"],"published":"2026-07-24","updated":"2026-07-24","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q3g2-m552-3r9c","references":[{"url":"https://github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9c"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64785"},{"url":"https://github.com/apple/swift-nio-http2/commit/45bdf670248be5f16ec0340e125dca285536f0fb"},{"url":"https://github.com/apple/swift-nio-http2/commit/48bfd9067d7d1d15c4789440127a0cf36222ea43"},{"url":"https://github.com/apple/swift-nio-http2/releases/tag/1.45.0"},{"url":"https://github.com/advisories/GHSA-q3g2-m552-3r9c"}],"tags":["ghsa","swift"],"epss":0.00181,"epssPercentile":0.07878,"ingestedAt":"2026-07-24T22:40:26.881Z","slug":"CVE-2026-64785","body":"## Overview\n\n## Summary\n\nSwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let\nCR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend\nthrough NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling\nor response splitting.\n\n## Impact\n\nTwo related gaps in inbound header validation, against any application\nusing HTTP2ToHTTP1Codec (or HTTP2FramePayloadToHTTP1Codec) to front an\nHTTP/1.1 backend:\n\nRegular header field values were only checked against a forbidden-name\nlist (connection, transfer-encoding, proxy-connection, keep-alive,\nupgrade); the value itself was never inspected. An attacker-controlled\nregular header field value containing CR or LF passed validation and, once\nserialized as `name: value CRLF` by the codec, terminated the field early\nand injected extra header lines into the outbound HTTP/1.1 message.\n\nPseudo-header values (`:path` in particular) were only checked against\nCR, LF and NUL. A `:path` value containing SP serializes into the\nrequest-target of `METHOD SP request-target SP HTTP-version CRLF`, so a\nvalue like `/a HTTP/1.1` produces `GET /a HTTP/1.1 HTTP/1.1` — a\nparser-differential request line depending on whether a downstream reader\ntakes the first or last SP-delimited token as the version.\n\nNeither of these is reachable on a stock pipeline: NIOHTTP1's outbound\nvalidator (`enableOutboundHeaderValidation`, on by default) already rejects\nthese characters on write. The exposure is pipelines that skip outbound\nvalidation, or any code that reads validated-looking `HTTPRequestHead.headers`\nand forwards the values on trusting that HTTP/2 already checked them.\n\n## Fix\n\nFixed in 48bfd90 and 45bdf67.\n\n## Mitigation\n\nUpgrade to 1.45.0\n\n## Affected packages\n\n- `swift-nio-http2 < 1.45.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `swift-nio-http2 1.45.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}