Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-24666

25
FAUCET Score

CVE-2022-24666 is a Denial of Service vulnerability affecting all versions of swift-nio-http2 from 1.0.0 to 1.19.1. A logical error in parsing specially crafted HTTP/2 HEADERS frames containing priority information without other data causes an immediate process crash. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low attack complexity, and high impact on availability, as it can be easily and repeatedly triggered by any network peer. While there are no known active exploits, public exploit code, or significant community discussion, the low effort required for exploitation poses a substantial risk to affected services.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.19.2CPE matchmatch criteria
cpe:2.3:a:apple:swiftnio_http\/2:*:*:*:*:*:swift:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.35%
Probability of exploitation in next 30 days
EPSS Percentile
68.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0135 is in the 49th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

djangopatch availablevia llm_extracted
falcopatch availablevia llm_extracted
swiftpatch availablevia ghsa
Product: github.com/apple/swift-nio-http2Fixed in: 1.19.2

Vendor Advisories (3)

swiftGHSA-ccw9-q5h2-8c2whigh

swift-nio-http2 vulnerable to denial of service via invalid HTTP/2 HEADERS frame length

May 18, 2023
falcollm-falco-25d37518454097e4

Denial of service in swift-nio-http2 from specially crafted HTTP/2 HEADERS frame.

djangollm-django-48938bd81e764d15

CVE-2022-24666

References

github.com / apple/swift-nio-http2/security/advisories/GHSA-ccw9-q5h2-8c2w
Third Party Advisory