CVE-2026-28898
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.
| Vendor | apple |
| Product | swift-nio-http2 |
| Ecosystems | |
| Industries | Technology |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for apple swift-nio-http2
Be the first to know when new medium vulnerabilities affecting apple swift-nio-http2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apple / swift-nio-http2
0 < 1.44.1