HTTP Request Smuggling and Response Splitting in SwiftNIO HTTP/2 by Apple
CVE-2026-64785
Currently unrated
What is CVE-2026-64785?
A vulnerability in SwiftNIO HTTP/2 stems from inadequate validation of inbound HEADERS frames. This weakness allows control characters such as CR, LF, NUL, and SP to bypass checks, reaching an HTTP/1.1 backend through the NIOHTTP2's HTTP/2-to-HTTP/1 codec. The result can lead to significant issues including HTTP request smuggling and response splitting, compromising the integrity and security of data transmitted between clients and servers. A fix has been implemented in SwiftNIO HTTP/2 version 1.45.0 to mitigate this risk.
Affected Version(s)
swift-nio-http2 0 < 1.45.0