CVE-2022-24667 is a Denial of Service (DoS) vulnerability affecting swift-nio-http2 versions 1.0.0 to 1.19.1, caused by improper handling of specially crafted HPACK-encoded header blocks. An unauthenticated network attacker can send these malicious blocks, leading to immediate process crashes and service disruption. With a CVSS score of 7.5 (High), this low-effort attack has a high impact on availability, though it lacks direct confidentiality or integrity risks. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.19.2CPE matchmatch criteria | cpe:2.3:a:apple:swiftnio_http\/2:*:*:*:*:*:swift:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encoding
May 18, 2023Denial of service in swift-nio-http2 from specially crafted HPACK-encoded header block.
CVE-2022-24667