ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.
References
| Link | Resource |
|---|---|
| https://github.com/apple/servicetalk/security/advisories/GHSA-56h2-h3h4-m9x6 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-08-12 21:17
Updated : 2026-09-03 19:19
NVD link : CVE-2026-65370
Mitre link : CVE-2026-65370
CVE.ORG link : CVE-2026-65370
JSON object : View
Products Affected
apple
- servicetalk
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
