Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-24667

24
FAUCET Score

CVE-2022-24667 is a Denial of Service (DoS) vulnerability affecting swift-nio-http2 versions 1.0.0 to 1.19.1, caused by improper handling of specially crafted HPACK-encoded header blocks. An unauthenticated network attacker can send these malicious blocks, leading to immediate process crashes and service disruption. With a CVSS score of 7.5 (High), this low-effort attack has a high impact on availability, though it lacks direct confidentiality or integrity risks. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.19.2CPE matchmatch criteria
cpe:2.3:a:apple:swiftnio_http\/2:*:*:*:*:*:swift:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.12%
Probability of exploitation in next 30 days
EPSS Percentile
62.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0112 is in the 41st percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

djangopatch availablevia llm_extracted
falcopatch availablevia llm_extracted
swiftpatch availablevia ghsa
Product: github.com/apple/swift-nio-http2Fixed in: 1.19.2

Vendor Advisories (3)

swiftGHSA-w3f6-pc54-gfw7high

swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encoding

May 18, 2023
falcollm-falco-91d3d844424bead2

Denial of service in swift-nio-http2 from specially crafted HPACK-encoded header block.

djangollm-django-244e1d71ccc658b1

CVE-2022-24667

References

github.com / apple/swift-nio-http2/security/advisories/GHSA-w3f6-pc54-gfw7
Third Party Advisory