CVE-2026-43678
EUVD-2026-6357720.08.2026, 19:16
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apple | swiftnio | 𝑥 < 2.101.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration