CVE-2026-65370: Apple Servicetalk

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.

Affected products

  • Apple Servicetalk: before 0.42.65 (fixed in 0.42.65)

Published 2026-08-12. Last modified 2026-09-03.