CVE-2022-3252 is a denial-of-service vulnerability in SwiftNIO Extras' HTTPRequestDecompressor and HTTPResponseDecompressor components, affecting Apple SwiftNIO Extras. The flaw stems from improper detection of complete HTTP body decompression, allowing an attacker to send trailing junk data that causes an infinite loop and livelock. Rated 7.5 HIGH on CVSS, this low-effort attack requires no privileges and can lead to high availability impact, as the process becomes unavailable without immediately crashing. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.2CPE matchmatch criteria | cpe:2.3:a:apple:swift-nio-extras:*:*:*:*:*:*:*:* | ||
>= 1.10.0, < 1.10.3CPE matchmatch criteria | cpe:2.3:a:apple:swift-nio-extras:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.14.0CPE matchmatch criteria | cpe:2.3:a:apple:swift-nio-extras:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SwiftNIO Extras vulnerable to improper detection of complete HTTP body decompression
Jun 7, 2023Improper detection of complete HTTP body decompression in SwiftNIO Extras leading to denial of service.
CVE-2022-3252