CVE-2019-8849: Apple Swiftnio SSL
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1. A SwiftNIO application using TLS may be able to execute arbitrary code.
Affected products
- Apple Swiftnio SSL: before 2.4.1 (fixed in 2.4.1)
Published 2019-12-18. Last modified 2026-06-17.