Apple Swift-Crypto vulnerabilities
2 known vulnerabilities affecting apple/swift-crypto.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-28815P3HIGHCVSS 7.5≥ 4.0.0, < 4.3.12026-04-03
CVE-2026-28815 [HIGH] CWE-125 CVE-2026-28815: A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read
A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulation path, potentially causing a crash or memory disclosure depending on runtime protections. This issue is fixed in swift-crypto version 4.3.1.
ghsanvdosv
CVE-2026-43823P3HIGHCVSS 7.5≥ 3.2.0, ≤ 4.5.1fixed in 4.5.12026-07-23
CVE-2026-43823 [HIGH] CWE-415 CVE-2026-43823: When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-f
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto ve
nvd