← Vulnerability feed

Vulnerability record · CVE-2026-64785 · published 23 July 2026

CVE-2026-64785: Apple swiftnio http\/2 http request smuggling vulnerability

Apple · Swiftnio Http\/2

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.

5.3 CVSS 3.1 Medium EPSS 0.29% · top 80.5% CWE-444 · HTTP request smuggling
5.3CVSS 3.1 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
1 Sep 2026Last modified by NVD

Description

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-64785 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2022-0618Apple swiftnio http\/2 vulnerabilityA program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This …EPSS 1.3%7.5CVE-2022-24667Apple swiftnio http\/2 integer overflow vulnerabilityA program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded heade…EPSS 1.1%7.5CVE-2022-24668Apple swiftnio http\/2 vulnerabilityA program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack aff…EPSS 1.1%7.5CVE-2022-24666Apple swiftnio http\/2 vulnerabilityA program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This …EPSS 1.4%5.3CVE-2026-28898Apple swiftnio http\/2 vulnerabilityswift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/…EPSS 0.31%6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed7.5CVE-2025-61884Oracle E-Business Suite Configurator pre-auth data exposure flawOracle Configurator in Oracle E-Business Suite 12.2.3 through 12.2.14 exposes a vulnerability reachable over HTTP without authentication. A successfu…KEVEPSS 96%analysed

Source: NIST National Vulnerability Database (record CVE-2026-64785), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.