Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64785

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

A flaw was found in SwiftNIO HTTP/2. This vulnerability allows a remote attacker to perform HTTP request smuggling or response splitting. The issue stems from insufficient validation of incoming HTTP/2 HEADERS frames, which are parts of an HTTP/2 request. This allows special control characters, such as carriage return (CR) and line feed (LF), to reach an HTTP/1.1 backend, potentially bypassing security controls and enabling malicious manipulation of web requests or responses.

Отчет

This vulnerability in SwiftNIO HTTP/2, which could lead to HTTP request smuggling or response splitting due to incomplete header validation, does not affect Red Hat products. Red Hat's analysis indicates that the affected component is not present or not configured in a vulnerable manner within supported offerings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesswift-langNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-93
https://bugzilla.redhat.com/show_bug.cgi?id=2506592swift-nio-http2: SwiftNIO HTTP/2: HTTP Request Smuggling and Response Splitting via Incomplete Header Validation

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
9 дней назад

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.

CVSS3: 5.3
github
8 дней назад

swift-nio-http2: Missing CR/LF/NUL validation in header values

5.3 Medium

CVSS3