Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-28898

AI Predicted 5.3 Difficulty: Moderate EPSS 0.19% · P9

Affected Version Matrix 1

VendorProductVersion RangeStatus
Appleswift-nio-http2< 1.44.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-28898

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apple swift-nio-http2 输出处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apple swift-nio-http2是美国Apple公司开源的一个HTTP/2协议的Swift实现组件。 Apple swift-nio-http2 1.44.1之前版本存在输出处理不当漏洞,该漏洞源于HTTP/2-to-HTTP/1.1编解码器未验证伪标头值中的控制字符,可能导致包含CR、LF或NUL字节的请求或响应被以连接错误处理。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Appleswift-nio-http2 0 ~ 1.44.1 -

II. Public POCs for CVE-2026-28898

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-28898

登录查看更多情报信息。

Vendor Advisories for CVE-2026-28898 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-28898

No comments yet


Leave a comment