CVE-2026-43678P4MEDIUMCVSS 5.3fixed in 2.101.02026-08-20
CVE-2026-43678 [MEDIUM] CWE-20 CVE-2026-43678: An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingb
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
nvd