๐Ÿ” CVE Alert

CVE-2026-28898

MEDIUM 5.3
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.

Vendor apple
Product swift-nio-http2
Ecosystems
Industries
Technology
Published Jun 25, 2026
Last Updated Jun 25, 2026
Stay Ahead of the Next One

Get instant alerts for apple swift-nio-http2

Be the first to know when new medium vulnerabilities affecting apple swift-nio-http2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apple / swift-nio-http2
0 < 1.44.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/advisories/GHSA-4px2-pw77-vc85