CVE-2026-64785

MEDIUM

swift-nio-http2 <1.45.0: HTTP request smuggling & response splitting via unvalidated HEADERS frame chars

Title source: llm
STIX 2.1

Description

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.

Scores

CVSS v3 5.3
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-444
Status published
Products (2)
Apple/swift-nio-http2 < 1.45.0
SwiftURL/swift-nio-http2 0 - 1.45.0SwiftURL
Published Jul 23, 2026
Tracked Since Jul 24, 2026