VYPR
Medium severity5.3NVD Advisory· Published Aug 20, 2026· Updated Aug 20, 2026

CVE-2026-43678

CVE-2026-43678

Description

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.