Swift Project Swiftnio Http2 vulnerabilities
4 known vulnerabilities affecting swift_project/swiftnio_http2.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4
Vulnerabilities
Page 1 of 1
CVE-2022-24666P3HIGHCVSS 7.5≥ 1.0.0, < unspecified≥ unspecified, ≤ 1.19.12022-02-09
CVE-2022-24666 [HIGH] CWE-130 CVE-2022-24666: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS frame where the frame contains priority information without
nvd
CVE-2022-0618P3HIGHCVSS 7.5≥ 1.0.0, < unspecified≥ unspecified, ≤ 1.19.22022-03-10
CVE-2022-0618 [HIGH] CWE-130 CVE-2022-0618: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame where the frame contains padding information without any other data. This logical error caused confusion
nvd
CVE-2022-24668P3HIGHCVSS 7.5≥ 1.0.0, < unspecified≥ unspecified, ≤ 1.19.12022-02-09
CVE-2022-24668 [HIGH] CWE-241 CVE-2022-24668: A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error after frame parsing but before frame handling. ORIGIN and ALTSVC frames are not currently supported
nvd
CVE-2022-24667P3HIGHCVSS 7.5≥ 1.0.0, < unspecified≥ unspecified, ≤ 1.19.12022-02-09
CVE-2022-24667 [HIGH] CWE-190 CVE-2022-24667: A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network pee
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of implementation errors in the parsing of HPACK-encoded header blocks that allow maliciously crafted HPA
nvd