VDB
CVE-2026-64785
CVE-2026-64785
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Reported by apple · Published July 23, 2026
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | swift-nio-http2 | 0 |
| SwiftURL | swift-nio-http2 | 0 |
| Apple | swift-nio-http2 | 0, 0, 0 |
Timeline
- Jul 23, 2026 CVE Published
- Jul 24, 2026 CVE Updated
- Jul 24, 2026 Coalition ESS Score
- Jul 25, 2026 EPSS Score
- Jul 26, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-64785 advisory
- https://github.com/advisories/GHSA-q3g2-m552-3r9c advisory
- https://github.com/apple/swift-nio-http2/commit/45bdf670248be5f16ec0340e125dca285536f0fb patch
- https://github.com/apple/swift-nio-http2/commit/48bfd9067d7d1d15c4789440127a0cf36222ea43 patch
- https://github.com/apple/swift-nio-http2/releases/tag/1.45.0 url