Medium severity5.3NVD Advisory· Published Aug 20, 2026· Updated Aug 20, 2026
CVE-2026-43678
CVE-2026-43678
Description
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
Affected products
1- Range: >=2.101.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.