SwiftURL incidents

Recent SwiftURL vulnerabilities and malicious packages from OSV and CISA KEV, enriched with EPSS exploit probability.

HIGHSwiftURL

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

SwiftNIO: Out-of-bounds write via ByteBuffer index and length UInt32 overflow

3 months ago
MODERATESwiftURL

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length

3 months ago
MODERATESwiftURL

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

SwiftNIO: CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator

3 months ago
HIGHSwiftURL

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

SwiftNIO NIOHTTP1: HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS

3 months ago
MEDIUMSwiftURL

Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection

Sparkle's AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection

3 months ago
CRITICALSwiftURL

Sparkle Signing Checks Bypass

Sparkle Signing Checks Bypass

1 year ago
CRITICALSwiftURL

wasm3 uncontrolled memory allocation vulnerability

wasm3 uncontrolled memory allocation vulnerability

pywasm3: all versions

1 year ago
HIGHSwiftURL

Un-sanitized metric name or labels can be used to take over exported metrics

Un-sanitized metric name or labels can be used to take over exported metrics

2 years ago
HIGHSwiftURL

Vapor contains an integer overflow in URI leading to potential host spoofing

Vapor contains an integer overflow in URI leading to potential host spoofing

2 years ago
MEDIUMSwiftURL

HTTP/2 Stream Cancellation Attack

HTTP/2 Stream Cancellation Attack

org.apache.tomcat:tomcat-coyote: 11.0.0-M1 → 11.0.0-M12

2 years ago
MEDIUMSwiftURL

Vapor's incorrect request error handling triggers server crash

Vapor's incorrect request error handling triggers server crash

2 years ago
HIGHSwiftURL

Denial of service via HTTP/2 HEADERS frames padding

Denial of service via HTTP/2 HEADERS frames padding

github.com/apple/swift-nio-http2: 1.0.0 → 1.20

3 years ago

Tooling for SwiftURL

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

All ecosystems

AlmaLinux:10AlmaLinux:8AlmaLinux:9GitHub ActionsGohexMavenNuGetPackagistPubPyPIRubyGemscrates.ionpm