VYPR

swift-nio-ssh

by Apple Inc.

CVEs (2)

  • CVE-2026-43678MedAug 20, 2026
    risk 0.27cvss 5.3epss

    An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in…

  • CVE-2026-43798Aug 20, 2026
    risk 0.00cvss epss

    A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.