CVE-2026-43678
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Aug 20, 2026
Vendor
unknown
Description
An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0.