Swift vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-0040Highgithub.com/swift-server/async-http-client: Async HTTP Client has CRLF Injection vulnerability in HTTP request headersCVE-2021-36154Mediumgithub.com/grpc/grpc-swift: Uncontrolled Recursion in HTTP2ToRawGRPCServerCodecCVE-2022-24668Highgithub.com/apple/swift-nio-http2: swift-nio-http2 vulnerable to denial of service via ALTSVC or ORIGIN framesCVE-2022-24666Highgithub.com/apple/swift-nio-http2: swift-nio-http2 vulnerable to denial of service via invalid HTTP/2 HEADERS frame lengthGHSA-MGC4-WQV7-4PXMCriticalgithub.com/apple/swift-nio: SwiftNIO vulnerable to HTTP request smuggling using malformed Transfer-Encoding headerCVE-2022-24667Highgithub.com/apple/swift-nio-http2: swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encodingCVE-2023-31136Lowgithub.com/vapor/postgres-nio: PostgresNIO processes unencrypted bytes from man-in-the-middleCVE-2022-4899Highgithub.com/facebook/zstd: zstd vulnerable to buffer overrunCVE-2019-8849Criticalgithub.com/apple/swift-nio-ssl: SwiftNIO SSL arbitrary code execution vulnerability

Stop the waste.
Protect your environment with Kodem.