Vulnerabilities in Swift Project
10 resultsVexday analysis
Swift Project apresenta um perfil de risco baixo com 10 CVEs catalogadas, nenhuma sob ataque ativo (KEV) ou com severidade crítica. A fraqueza dominante é CWE-130, sem novas publicações nos últimos 90 dias, indicando um panorama estável e sem pressão imediata de exploração.
CVE-2022-24666—A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 fraEPSS 1.4%CVE-2022-0618—A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 fraEPSS 1.3%CVE-2022-24667—A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoEPSS 1.1%CVE-2022-24668—A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This aEPSS 1.1%CVE-2022-3918HIGHA program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In EPSS 0.8%CVE-2022-3252—Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HEPSS 0.7%CVE-2022-1642—A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JEPSS 0.6%CVE-2022-3215HIGHNIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1EPSS 0.6%CVE-2023-0040HIGHVersions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerabEPSS 0.5%CVE-2025-0343HIGHSwift ASN.1 can be caused to crash when parsing certain BER/DER constructions. This crash is caused by a confusion in the ASN.1 library itseEPSS 0.3%