CVE-2026-64785 Details
Description
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.
A vulnerability exists in Apple SwiftNIO HTTP/2 versions prior to 1.45.0, due to inadequate validation of inbound HEADERS frames. This flaw allows control characters such as CR, LF, NUL, and SP to be transmitted to an HTTP/1.1 backend via NIOHTTP2's HTTP/2-to-HTTP/1 codec. The lack of proper validation enables HTTP request smuggling or response splitting attacks.
Users are advised to upgrade to SwiftNIO HTTP/2 version 1.45.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9c | [email protected] | Vendor AdvisoryPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple swiftnio http/2 | < 1.45.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 1, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | New CVE Received | [email protected] |