Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple swift-nio-http2 输出处理不当漏洞
Vulnerability Description
Apple swift-nio-http2是美国Apple公司开源的一个HTTP/2协议的Swift实现组件。 Apple swift-nio-http2 1.44.1之前版本存在输出处理不当漏洞,该漏洞源于HTTP/2-to-HTTP/1.1编解码器未验证伪标头值中的控制字符,可能导致包含CR、LF或NUL字节的请求或响应被以连接错误处理。
CVSS Information
N/A
Vulnerability Type
N/A