Tagged “swift”
CVEs tagged swift, newest first.
7 CVEsRSS
CVE-2026-64785Medium· 5.3swift-nio-http2: Missing CR/LF/NUL validation in header values
swift-nio-http2: Missing CR/LF/NUL validation in header values
▾ Sunlitswift-nio-http2 · swift-nio-http2EPSS 0.18%via GHSA
CVE-2026-28970MediumSwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
▾ Sunlitapple · github.com/apple/swift-niovia GHSA
CVE-2026-43671HighSwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow
SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow
▾ Twilightapple · github.com/apple/swift-niovia GHSA
CVE-2026-28980HighSwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
▾ Twilightapple · github.com/apple/swift-niovia GHSA
CVE-2026-28975MediumNIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
▾ Sunlitapple · github.com/apple/swift-nio-extrasvia GHSA
CVE-2026-28898LowSwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
▾ Sunlitapple · github.com/apple/swift-nio-http2EPSS 0.31%via GHSA
CVE-2024-27529High· 8.4wasm3 uncontrolled memory allocation vulnerability
wasm3 uncontrolled memory allocation vulnerability
▾ Twilightshareup · github.com/shareup/wasm-interpreter-appleEPSS 0.26%via OSV