swift-nio-http2: Missing CR/LF/NUL validation in header values
SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let
CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend
through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling
or response splitting.
Two related gaps in inbound header validation, against any application
using HTTP2ToHTTP1Codec (or HTTP2FramePayloadToHTTP1Codec) to front an
HTTP/1.1 backend:
Regular header field values were only checked against a forbidden-name
list (connection, transfer-encoding, proxy-connection, keep-alive,
upgrade); the value itself was never inspected. An attacker-controlled
regular header field value containing CR or LF passed validation and, once
serialized as name: value CRLF by the codec, terminated the field early
and injected extra header lines into the outbound HTTP/1.1 message.
Pseudo-header values (:path in particular) were only checked against
CR, LF and NUL. A :path value containing SP serializes into the
request-target of METHOD SP request-target SP HTTP-version CRLF, so a
value like /a HTTP/1.1 produces GET /a HTTP/1.1 HTTP/1.1 — a
parser-differential request line depending on whether a downstream reader
takes the first or last SP-delimited token as the version.
Neither of these is reachable on a stock pipeline: NIOHTTP1's outbound
validator (enableOutboundHeaderValidation, on by default) already rejects
these characters on write. The exposure is pipelines that skip outbound
validation, or any code that reads validated-looking HTTPRequestHead.headers
and forwards the values on trusting that HTTP/2 already checked them.
Fixed in 48bfd90 and 45bdf67.
Upgrade to 1.45.0
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity low, availability none.
The score comes from this vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE-2026-64785 is classified as CWE-113: HTTP Response Splitting. Unescaped input reaches an HTTP header, letting an attacker inject line breaks and forge additional headers or responses.
CVE-2026-64785 is recorded against 2 packages.
Published on 24 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)
These advisories are the same class of weakness (CWE-113: HTTP Response Splitting) in other software:
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| swift-nio-http2 | — | — |
| unknown | — | — |
References
Vulnerability Monitoring
CVE-2026-64785 is rated CVSS 5.3 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.
Set Up Free Alerts →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.