Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
CVE-2026-64785
swift-nio-http2: Missing CR/LF/NUL validation in header values
CVE-2026-28898
SwiftNIO HTTP/2: HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
CVE-2026-28975
NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
CVE-2026-28980
SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
CVE-2026-43671
SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow
CVE-2026-28970
SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
CVE-2026-47122
Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection
CVE-2026-47121
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
container: pf Rule Injection via Domain Name Argument in `container system dns create --localhost` Command
CVE-2026-30867
CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing
CVE-2026-28815
Swift Crypto: X-Wing HPKE Decapsulation Accepts Malformed Ciphertext Length
CVE-2026-28499
LeafKit's HTML escaping may be skipped for Collection values, enabling XSS
CVE-2026-27120
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
CVE-2026-20613
Container and Containerization archive extraction does not guard against escapes from extraction base directory.
CVE-2026-23886
Swift W3C TraceContext vulnerable to a malformed HTTP header causing a crash
jose-swift has JWT Signature Verification Bypass via None Algorithm
AWS SDK for Swift adopted defense in depth enhancement for region parameter value
swift-nio-http2 affected by HTTP/2 MadeYouReset vulnerability
CVE-2025-30405
ExecuTorch integer overflow vulnerability
CVE-2025-54949
ExecuTorch heap buffer overflow vulnerability
Showing 1 - 20 of 1,000+ results