High severity7.5NVD Advisory· Published May 31, 2022· Updated Jun 17, 2026
CVE-2022-31005
CVE-2022-31005
Description
Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/vapor/vaporSwiftURL | < 4.60.3 | 4.60.3 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/vapor/vapor/commit/953a349b539b3e0d3653585c8ffb50c427986df1nvdPatchThird Party AdvisoryWEB
- github.com/vapor/vapor/security/advisories/GHSA-vj2m-9f5j-mpr5nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vj2m-9f5j-mpr5ghsaADVISORY
- github.com/vapor/vapor/releases/tag/4.60.3nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-31005ghsaADVISORY
News mentions
0No linked articles in our index yet.