Apple swift-nio-http2是美国Apple公司开源的一个HTTP/2协议的Swift实现组件。 Apple swift-nio-http2 1.45.0之前版本存在安全漏洞,该漏洞源于SwiftNIO HTTP/2未对入站HEADERS帧中的CR、LF、NUL、SP等控制字符进行验证,导致这些字符通过NIOHTTP2的HTTP/2到HTTP/1编解码器到达HTTP/1.1后端,从而可能引发HTTP请求夹带或响应拆分攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apple | swift-nio-http2 | < 1.45.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apple | swift-nio-http2 | 0 ~ 1.45.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43820 | Apple SwiftNIO SSL 安全漏洞 | |
| CVE-2026-43823 | Apple Swift Crypto 安全漏洞 |
No comments yet