Medium severity5.3NVD Advisory· Published Jul 23, 2026· Updated Sep 1, 2026
CVE-2026-64785
CVE-2026-64785
Description
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
swift-nio-http2SwiftURL | < 1.45.0 | 1.45.0 |
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: >=1.45.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-q3g2-m552-3r9cghsaADVISORY
- github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9cnvdVendor AdvisoryPatchWEB
- nvd.nist.gov/vuln/detail/CVE-2026-64785ghsaADVISORY
- github.com/apple/swift-nio-http2/commit/45bdf670248be5f16ec0340e125dca285536f0fbghsaWEB
- github.com/apple/swift-nio-http2/commit/48bfd9067d7d1d15c4789440127a0cf36222ea43ghsaWEB
- github.com/apple/swift-nio-http2/releases/tag/1.45.0ghsaWEB
News mentions
0No linked articles in our index yet.