Apple
Apple Swiftnio: vulnerabilidades y CVE
Apple Swiftnio tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-43678 | Media (5.3) | 0.37% | — | 20 ago 2026 | An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the… |
| CVE-2022-3215 | Alta (7.5) | 0.65% | — | 28 sept 2022 | NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server accepts user generated input from an incoming request and reflects it… |
| CVE-2019-9518 | Alta (7.5) | 25% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These… |
| CVE-2019-9517 | Alta (7.5) | 28% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they… |
| CVE-2019-9516 | Media (6.5) | 56% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman… |
| CVE-2019-9515 | Alta (7.5) | 87% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one… |
| CVE-2019-9514 | Alta (7.5) | 83% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream… |
| CVE-2019-9513 | Alta (7.5) | 82% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that… |
| CVE-2019-9512 | Alta (7.5) | 83% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses.… |
| CVE-2019-9511 | Alta (7.5) | 60% | — | 13 ago 2019 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified… |
| CVE-2018-4281 | Crítica (9.8) | 1.0% | — | 11 ene 2019 | In SwiftNIO before 1.8.0, a buffer overflow was addressed with improved size validation. |