CVE-2023-44386

Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vapor:vapor:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:25

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-05 18:15

Updated : 2024-11-21 08:25


NVD link : CVE-2023-44386

Mitre link : CVE-2023-44386

CVE.ORG link : CVE-2023-44386


JSON object : View

Products Affected

vapor

  • vapor
CWE
CWE-231

Improper Handling of Extra Values

CWE-617

Reachable Assertion

CWE-696

Incorrect Behavior Order