CVE-2026-64785

CVE-2026-64785 is a medium-severity security vulnerability in swift-nio-http2 (swift), affecting versions < 1.45.0. It is fixed in 1.45.0.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

swift-nio-http2: Missing CR/LF/NUL validation in header values

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let
CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend
through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling
or response splitting.

Mitigation

Upgrade to 1.45.0

Impact

Two related gaps in inbound header validation, against any application
using HTTP2ToHTTP1Codec (or HTTP2FramePayloadToHTTP1Codec) to front an
HTTP/1.1 backend:

Regular header field values were only checked against a forbidden-name
list (connection, transfer-encoding, proxy-connection, keep-alive,
upgrade); the value itself was never inspected. An attacker-controlled
regular header field value containing CR or LF passed validation and, once
serialized as name: value CRLF by the codec, terminated the field early
and injected extra header lines into the outbound HTTP/1.1 message.

Pseudo-header values (:path in particular) were only checked against
CR, LF and NUL. A :path value containing SP serializes into the
request-target of METHOD SP request-target SP HTTP-version CRLF, so a
value like /a HTTP/1.1 produces GET /a HTTP/1.1 HTTP/1.1, a
parser-differential request line depending on whether a downstream reader
takes the first or last SP-delimited token as the version.

Neither of these is reachable on a stock pipeline: NIOHTTP1's outbound
validator (enableOutboundHeaderValidation, on by default) already rejects
these characters on write. The exposure is pipelines that skip outbound
validation, or any code that reads validated-looking HTTPRequestHead.headers
and forwards the values on trusting that HTTP/2 already checked them.

CVE-2026-64785 has a CVSS score of 5.3 (Medium). The vector is network-reachable, no privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (1.45.0); upgrading removes the vulnerable code path.

Affected versions

swift-nio-http2 (< 1.45.0)

Security releases

swift-nio-http2 → 1.45.0 (swift)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Fixed in 48bfd90 and 45bdf67.

Frequently Asked Questions

  1. What is CVE-2026-64785? CVE-2026-64785 is a medium-severity security vulnerability in swift-nio-http2 (swift), affecting versions < 1.45.0. It is fixed in 1.45.0.
  2. How severe is CVE-2026-64785? CVE-2026-64785 has a CVSS score of 5.3 (Medium). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Which versions of swift-nio-http2 are affected by CVE-2026-64785? swift-nio-http2 (swift) versions < 1.45.0 is affected.
  4. Is there a fix for CVE-2026-64785? Yes. CVE-2026-64785 is fixed in 1.45.0. Upgrade to this version or later.
  5. Is CVE-2026-64785 exploitable, and should I be worried? Whether CVE-2026-64785 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  6. What actually determines whether CVE-2026-64785 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  7. How do I fix CVE-2026-64785? Upgrade swift-nio-http2 to 1.45.0 or later.

Stop the waste.
Protect your environment with Kodem.