An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.
References
| Link | Resource |
|---|---|
| https://github.com/apple/swift-nio/security/advisories/GHSA-qcc5-f287-vgmq | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-20 19:16
Updated : 2026-08-28 17:48
NVD link : CVE-2026-43678
Mitre link : CVE-2026-43678
CVE.ORG link : CVE-2026-43678
JSON object : View
Products Affected
apple
- swiftnio
