A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.
References
| Link | Resource |
|---|---|
| https://github.com/apple/swift-nio-ssh/security/advisories/GHSA-998x-vgvp-xwpc | Vendor Advisory Patch |
Configurations
History
No history.
Information
Published : 2026-08-20 21:17
Updated : 2026-09-03 13:35
NVD link : CVE-2026-43798
Mitre link : CVE-2026-43798
CVE.ORG link : CVE-2026-43798
JSON object : View
Products Affected
apple
- swiftnio_ssh
CWE
CWE-121
Stack-based Buffer Overflow
