CVE-2022-31005: high-severity vulnerability in vapor
Integer Overflow in Vapor's HTTP Range Request
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Vapor web framework versions before 4.60.3 contain an integer overflow bug in FileMiddleware that allows attackers to crash the application by sending specially crafted HTTP range requests. This vulnerability affects any Vapor application using FileMiddleware to serve files.
An integer overflow in Vapor's FileMiddleware HTTP range request handler (CWE-190) allows remote attackers to trigger a denial-of-service condition by sending malformed range headers that cause arithmetic overflow during request processing. The vulnerability requires FileMiddleware to be enabled and affects versions prior to 4.60.3; exploitation results in application crash without authentication.
In the same product, most dangerous first.