Feed/CVE-2026-43678
CVE-2026-43678MEDIUMCVSS 5.3

CVE-2026-43678

Published Aug 20, 2026·Updated Aug 20, 2026

NVD Description

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free