CVE-2022-24666 is a Denial of Service vulnerability affecting all versions of swift-nio-http2 from 1.0.0 to 1.19.1. A logical error in parsing specially crafted HTTP/2 HEADERS frames containing priority information without other data causes an immediate process crash. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low attack complexity, and high impact on availability, as it can be easily and repeatedly triggered by any network peer. While there are no known active exploits, public exploit code, or significant community discussion, the low effort required for exploitation poses a substantial risk to affected services.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.19.2CPE matchmatch criteria | cpe:2.3:a:apple:swiftnio_http\/2:*:*:*:*:*:swift:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.