CVE-2026-43678: Apple Swiftnio

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.

Affected products

  • Apple Swiftnio: before 2.101.0 (fixed in 2.101.0)

Published 2026-08-20. Last modified 2026-08-28.