CVE-2026-64785
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
| Vendor | apple |
| Product | swift-nio-http2 |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for apple swift-nio-http2
Be the first to know when new unknown vulnerabilities affecting apple swift-nio-http2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apple / swift-nio-http2
0 < 1.45.0