High severity7.7NVD Advisory· Published Jul 23, 2026· Updated Sep 4, 2026
CVE-2026-43820
CVE-2026-43820
Description
NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=2.37.2
Patches
Vulnerability mechanics
References
1- github.com/apple/swift-nio-ssl/security/advisories/GHSA-xfxg-9975-pc2jnvdVendor AdvisoryExploit
News mentions
0No linked articles in our index yet.