CVE-2026-64785: Apple Swiftnio http/2

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.

Affected products

  • Apple Swiftnio http/2: before 1.45.0 (fixed in 1.45.0)

Published 2026-07-23. Last modified 2026-09-01.