VYPR

Swiftnio SSL

by Apple Inc.

CVEs (2)

  • CVE-2019-8849CriDec 18, 2019
    risk 0.57cvss 9.8epss 0.02

    The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.

  • CVE-2026-43820HigJul 23, 2026
    risk 0.50cvss 7.7epss 0.00

    NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds…