CVE-2026-43820

Source
https://cve.org/CVERecord?id=CVE-2026-43820
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43820.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43820
Aliases
  • GHSA-xfxg-9975-pc2j
Published
2026-07-23T15:17:05.503Z
Modified
2026-09-06T08:07:53.695044Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

NIOSSLCertificate.subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.

References

Affected packages

Git / github.com/apple/swift-nio-ssl

Affected ranges

Type
GIT
Repo
https://github.com/apple/swift-nio-ssl
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:apple:swiftnio_ssl:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "2.18.0"
        },
        {
            "fixed": "2.37.2"
        }
    ]
}

Affected versions

2.*
2.18.0
2.19.0
2.20.0
2.20.1
2.20.2
2.21.0
2.22.0
2.22.1
2.23.0
2.23.1
2.24.0
2.25.0
2.26.0
2.27.0
2.27.1
2.27.2
2.28.0
2.29.0
2.29.1
2.29.2
2.29.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.34.1
2.35.0
2.36.0
2.36.1
2.37.0
2.37.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43820.json"