MEDIUMCVSS 5.3Vulnerability
CVE-2026-64785
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
Properties
- severity
- MEDIUM
- summary
- swift-nio-http2: Missing CR/LF/NUL validation in header values
- epss_score
- 0.00181
- cvss_score
- 5.3
- ghsa_published
- 2026-07-24T21:52:10Z
- source_url
- https://github.com/advisories/GHSA-q3g2-m552-3r9c
- ghsa_updated
- 2026-07-24T21:52:11Z
- ghsa_id
- GHSA-q3g2-m552-3r9c
- score
- 5.3
- cve_id
- CVE-2026-64785
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- published_at
- 2026-07-23T20:17:21.440
- last_modified
- 2026-09-01T13:08:24.200
- epss_percentile
- 0.0772
Related Entities (8)
DESCRIBED_BY (1)
→[Source]NVD
AFFECTS_PRODUCT (1)
→[Product]
ENRICHED_BY (1)
→[Source]FIRST EPSS
AFFECTS (1)
→[Software]swift/swift-nio-http2
HAS_WEAKNESS (2)
→[Weakness]Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
→[Weakness]Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]swift/swift-nio-http2
Explore deeper with Ninja Signal's threat intelligence graph