CVE-2022-3918 is a CRLF injection vulnerability affecting FoundationNetworking in swift-corelibs-foundation, allowing an attacker to insert extra headers or even craft entirely new requests by injecting CRLF sequences into URLRequest header values. With a CVSS score of 8.8 (HIGH), this vulnerability has a network attack vector, low attack complexity, and can lead to high impacts on confidentiality, integrity, and availability if unsanitized user input is used in headers. While the EPSS and FAUCET Risk Score indicate a moderate to high risk, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.7.3CPE matchmatch criteria | cpe:2.3:a:apple:swift_foundation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.