What is CVE-2026-64785?
SwiftNIO HTTP/2 library fails to validate control characters like CR, LF, NUL, and SP in inbound HEADERS frames, allowing them to reach an HTTP/1.1 backend via the HTTP/2-to-HTTP/1 codec, potentially enabling HTTP request smuggling or response splitting. Affected systems should immediately upgrade to the latest version of swift-nio-http2.
Azərbaycanca: SwiftNIO HTTP/2 kitabxanasında daxil olan HEADERS kadrları üzərində CR, LF, NUL, SP kimi idarəetmə simvollarının yoxlanılmaması HTTP/1.1 arxa xidmətinə hücumlar keçirməyə imkan verir, bu da HTTP sorğu qaçaqmalçılığı (request smuggling) və ya cavab parçalanması (response splitting) ilə nəticələnə bilər. Təsirə məruz qalan sistemlər dərhal swift-nio-http2 kitabxanasının ən son versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ1
What library is affected by CVE-2026-64785 and what types of attacks can it lead to?
The vulnerability was found in the SwiftNIO HTTP/2 library. The failure to validate control characters like CR, LF, NUL, and SP in inbound HEADERS frames allows attacks against an HTTP/1.1 backend, which can result in HTTP request smuggling or response splitting.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.