CVE-2026-43820High· 7.7▾ TwilightNIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 5.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
swiftnio_ssl >= 2.18.0, < 2.37.2Upgrade past the affected range:
swiftnio_ssl 2.37.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86900Medium· 6.5An out-of-bounds read issue was addressed with improved input validation
CVE-2026-84572High· 7.1An out-of-bounds read was addressed with improved bounds checking
CVE-2026-84565High· 7.1An out-of-bounds read was addressed with improved bounds checking
CVE-2026-86903Medium· 5.5An out-of-bounds read was addressed with improved input validation
CVE-2026-84597Medium· 6.5An out-of-bounds read issue was addressed with improved input validation
CVE-2026-84596Medium· 6.5An out-of-bounds read was addressed with improved bounds checking