{"id":"CVE-2026-64785","aliases":["GHSA-q3g2-m552-3r9c"],"url":"https://o3.security/vulnerability/CVE-2026-64785","summary":"swift-nio-http2: Missing CR/LF/NUL validation in header values","details":"SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.","published":"2026-07-23T20:17:21.440Z","modified":"2026-09-03T08:05:05.331371Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.00181,"percentile":0.0772,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"SwiftURL","name":"swift-nio-http2","fixedVersion":"1.45.0"}],"fix":null,"references":[{"type":"FIX","url":"https://github.com/apple/swift-nio-http2/security/advisories/GHSA-q3g2-m552-3r9c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-03T08:05:05.331371Z"}}