Swift Project

First CVE: Feb 9, 2022Active for: 4 years
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
3.3
Avg CVEs / Year
More Avg CVEs / Year than 24% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 75% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Swift Project as a CNA, 0.0% affect products that Swift Project develops as a vendor.

100.0%
Self-reported: 0Third-party: 10

Of all the CVEs published that affect products developed by Swift Project, 0.0% are self-published by Swift Project as a CNA.

100.0%
Self-published: 0Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by Swift Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2022
4 years ago
Most Recent CVE
Jan 15, 2025
555 days ago

Top CVEs

All CVEs published by Swift Project as a CNA, regardless of affected vendor or product.

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In this vulnerability, a client can insert
Jan 20, 20238.828NONO
Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently decompressing received HTTP request or response bodies. These tw
Sep 21, 20227.525NONO
A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch.
Jun 16, 20227.525NONO
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-ht
Feb 9, 20227.525NONO
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient val
Jan 18, 20237.524NONO
NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This occurs when a HTTP/1.1 server accepts user generated input fro
Sep 28, 20227.524NONO
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects al
Feb 9, 20227.524NONO
Swift ASN.1 can be caused to crash when parsing certain BER/DER constructions. This crash is caused by a confusion in the ASN.1 library itself which assumes that certain objects ca
Jan 15, 20257.521NONO
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a lo
Mar 10, 20227.519NONO
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versio
Feb 9, 20227.519NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA10 CVEs
Severity distribution among all CVEs352,231 CVEs
High
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Swift Project as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Swift Project as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs