VYPR

Swift package

github.com/swift-server/async-http-client

pkg:swift/github.com/swift-server/async-http-client

Vulnerabilities (1)

  • CVE-2023-0040Jan 18, 2023
    affected >= 1.13.0, < 1.13.2fixed 1.13.2

    Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they