HTTP Request Smuggling and Response Splitting in SwiftNIO HTTP/2 by Apple
CVE-2026-64785

Currently unrated

Key Information:

Vendor

Apple

Vendor
CVE Published:
23 July 2026

What is CVE-2026-64785?

A vulnerability in SwiftNIO HTTP/2 stems from inadequate validation of inbound HEADERS frames. This weakness allows control characters such as CR, LF, NUL, and SP to bypass checks, reaching an HTTP/1.1 backend through the NIOHTTP2's HTTP/2-to-HTTP/1 codec. The result can lead to significant issues including HTTP request smuggling and response splitting, compromising the integrity and security of data transmitted between clients and servers. A fix has been implemented in SwiftNIO HTTP/2 version 1.45.0 to mitigate this risk.

Affected Version(s)

swift-nio-http2 0 < 1.45.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.