Medium severity5.3NVD Advisory· Published Aug 20, 2026· Updated Aug 28, 2026
CVE-2026-43678
CVE-2026-43678
Description
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=2.101.0
Patches
Vulnerability mechanics
References
1- github.com/apple/swift-nio/security/advisories/GHSA-qcc5-f287-vgmqnvdVendor Advisory
News mentions
1- Apple Patches Six Vulnerabilities in macOS, watchOS, and Container TechVypr Intelligence · Aug 21, 2026