cbcvebase.

Apple Swiftnio Http 2 vulnerabilities

11 known vulnerabilities affecting apple/swiftnio_http_2.

Total CVEs
11
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH9MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 1.28.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2019-9515P3HIGHCVSS 7.5v1.5.02019-08-13
CVE-2019-9515 [HIGH] CVE-2019-9515: SwiftNIO HTTP/2 1.5.0 Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0 Product: SwiftNIO HTTP/2 Version: 1.5.0 CVE: CVE-2019-9515 Component: SwiftNIO HTTP/2 Impact: A HTTP/2 server may consume unbounded amounts of memory when receiving certain traffic patterns and eventually suffer resource exhaustion Description: This issue was addressed with improved buffer size management.
apple
CVE-2019-9512P3HIGHCVSS 7.5v1.5.02019-08-13
CVE-2019-9512 [HIGH] CVE-2019-9512: SwiftNIO HTTP/2 1.5.0 Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0 Product: SwiftNIO HTTP/2 Version: 1.5.0 CVE: CVE-2019-9512 Component: SwiftNIO HTTP/2 Impact: A HTTP/2 server may consume unbounded amounts of memory when receiving certain traffic patterns and eventually suffer resource exhaustion Description: This issue was addressed with improved buffer size management.
apple
CVE-2019-9514P3HIGHCVSS 7.5v1.5.02019-08-13
CVE-2019-9514 [HIGH] CVE-2019-9514: SwiftNIO HTTP/2 1.5.0 Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0 Product: SwiftNIO HTTP/2 Version: 1.5.0 CVE: CVE-2019-9514 Component: SwiftNIO HTTP/2 Impact: A HTTP/2 server may consume unbounded amounts of memory when receiving certain traffic patterns and eventually suffer resource exhaustion Description: This issue was addressed with improved buffer size management.
apple
CVE-2019-9518P3HIGHCVSS 7.5v1.5.02019-08-13
CVE-2019-9518 [HIGH] CVE-2019-9518: SwiftNIO HTTP/2 1.5.0 Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0 Product: SwiftNIO HTTP/2 Version: 1.5.0 CVE: CVE-2019-9518 Component: SwiftNIO HTTP/2 Impact: A HTTP/2 server may consume excessive CPU resources when receiving certain traffic patterns Description: This issue was addressed with improved input validation.
apple
CVE-2019-9516P3MEDIUMCVSS 6.5v1.5.02019-08-13
CVE-2019-9516 [MEDIUM] CVE-2019-9516: SwiftNIO HTTP/2 1.5.0 Apple Security Update: About the security content of SwiftNIO HTTP/2 1.5.0 Product: SwiftNIO HTTP/2 Version: 1.5.0 CVE: CVE-2019-9516 Component: SwiftNIO HTTP/2 Impact: A HTTP/2 server may consume unbounded amounts of memory when receiving certain traffic patterns and eventually suffer resource exhaustion Description: This issue was addressed with improved buffer size management.
apple
CVE-2022-24666P3HIGHCVSS 7.5≥ 1.0.0, < 1.19.22022-02-09
CVE-2022-24666 [HIGH] CWE-130 CVE-2022-24666: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS frame where the frame contains priority information without
nvd
CVE-2022-0618P3HIGHCVSS 7.5≥ 1.0.0, < 1.20.02022-03-10
CVE-2022-0618 [HIGH] CWE-130 CVE-2022-0618: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame where the frame contains padding information without any other data. This logical error caused confusion
nvd
CVE-2022-24668P3HIGHCVSS 7.5≥ 1.0.0, < 1.19.22022-02-09
CVE-2022-24668 [HIGH] CWE-241 CVE-2022-24668: A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error after frame parsing but before frame handling. ORIGIN and ALTSVC frames are not currently supported
nvd
CVE-2022-24667P3HIGHCVSS 7.5≥ 1.0.0, < 1.19.22022-02-09
CVE-2022-24667 [HIGH] CWE-190 CVE-2022-24667: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of implementation errors in the parsing of HPACK-encoded header blocks that allow maliciously crafted HPA
nvd
CVE-2026-28898P4MEDIUMCVSS 5.3fixed in 1.44.12026-06-25
CVE-2026-28898 [MEDIUM] CWE-116 CVE-2026-28898: swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control charact swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 tr
nvd
Apple Swiftnio Http 2 vulnerabilities | cvebase