Out-of-bounds Memory Access in NIOSSL Affecting Swift NIO SSL
CVE-2026-43820
Currently unrated
What is CVE-2026-43820?
The NIOSSL component of Swift NIO SSL is susceptible to an out-of-bounds memory access issue due to the mismanagement of Subject Alternative Names (SANs). While NIOSSL attempts to access a buffer associated with ASN1_STRING for SANs, not all SANs conform to this structure. Consequently, this flaw can lead to unintended memory access, potentially resulting in application crashes or exploitation opportunities. The issue has been addressed in swift-nio-ssl version 2.37.2, and users are recommended to update their installations to mitigate risks.
Affected Version(s)
swift-nio-ssl 0 < 2.37.2