---
id: CVE-2026-64785
aliases:
  - GHSA-q3g2-m552-3r9c
title: 'swift-nio-http2: Missing CR/LF/NUL validation in header values'
summary: 'swift-nio-http2: Missing CR/LF/NUL validation in header values'
severity: medium
cvss: 5.3
cwe:
  - CWE-113
  - CWE-444
vendor: swift-nio-http2
product: swift-nio-http2
ecosystem: swift
affected:
  - swift-nio-http2 < 1.45.0
patched:
  - swift-nio-http2 1.45.0
published: '2026-07-24'
updated: '2026-07-24'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-q3g2-m552-3r9c'
references:
  - url: >-
      https://github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9c
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64785'
  - url: >-
      https://github.com/apple/swift-nio-http2/commit/45bdf670248be5f16ec0340e125dca285536f0fb
  - url: >-
      https://github.com/apple/swift-nio-http2/commit/48bfd9067d7d1d15c4789440127a0cf36222ea43
  - url: 'https://github.com/apple/swift-nio-http2/releases/tag/1.45.0'
  - url: 'https://github.com/advisories/GHSA-q3g2-m552-3r9c'
tags:
  - ghsa
  - swift
epss: 0.00289
epssPercentile: 0.1914
ingestedAt: '2026-07-24T22:40:26.881Z'
---

## Overview

## Summary

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let
CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend
through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling
or response splitting.

## Impact

Two related gaps in inbound header validation, against any application
using HTTP2ToHTTP1Codec (or HTTP2FramePayloadToHTTP1Codec) to front an
HTTP/1.1 backend:

Regular header field values were only checked against a forbidden-name
list (connection, transfer-encoding, proxy-connection, keep-alive,
upgrade); the value itself was never inspected. An attacker-controlled
regular header field value containing CR or LF passed validation and, once
serialized as `name: value CRLF` by the codec, terminated the field early
and injected extra header lines into the outbound HTTP/1.1 message.

Pseudo-header values (`:path` in particular) were only checked against
CR, LF and NUL. A `:path` value containing SP serializes into the
request-target of `METHOD SP request-target SP HTTP-version CRLF`, so a
value like `/a HTTP/1.1` produces `GET /a HTTP/1.1 HTTP/1.1` — a
parser-differential request line depending on whether a downstream reader
takes the first or last SP-delimited token as the version.

Neither of these is reachable on a stock pipeline: NIOHTTP1's outbound
validator (`enableOutboundHeaderValidation`, on by default) already rejects
these characters on write. The exposure is pipelines that skip outbound
validation, or any code that reads validated-looking `HTTPRequestHead.headers`
and forwards the values on trusting that HTTP/2 already checked them.

## Fix

Fixed in 48bfd90 and 45bdf67.

## Mitigation

Upgrade to 1.45.0

## Affected packages

- `swift-nio-http2 < 1.45.0`

## Remediation

Upgrade to a patched release:

- `swift-nio-http2 1.45.0`
