Remote Downtime Vulnerability in NIOWebSocket Servers by Apple
CVE-2026-43678
5.3MEDIUM
What is CVE-2026-43678?
A remote peer can exploit a vulnerability in NIOWebSocket-based servers such as Vapor and Hummingbird by sending a specific 11-byte frame after the WebSocket handshake. This can lead to a denial of service, causing all active connections to drop until the server process is restarted. The issue is resolved in swift-nio version 2.101.0.
Affected Version(s)
swift-nio 0 < 2.101.0