Skip to content
AppleGHSA-mgc4-wqv7-4pxm

HTTP request smuggling using malformed Transfer-Encoding header

CriticalCVE-2019-15605 · Published Feb 17, 2020

### Impact Affected SwiftNIO systems are vulnerable to request smuggling attacks, in which they parse a given HTTP message differently from other network parties, potentially seeing a different number of requests than other servers. This can lead to failures of authentication, routing, and other issues. This vulnerability can be found in the bundled copy of the Node.JS HTTP parser used in the `NIOHTTP1` module. ### Workarounds No workaround is available, users must upgrade. ### References https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/#http-request-smuggling-using-malformed-transfer-encoding-header-critical-cve-2019-15605

GitHub advisory

Affected versions

PackageAffectedFixed in
swift-nio
Product
< 1.14.21.14.2
Details and references

More Apple advisories

All Apple
Advisory
Request/response decompression checks the size of compressed instead of decompressed bytes
HighMay 2, 2020
Executable Stack
MediumNov 25, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019
Apple: denial of service
HighAug 13, 2019

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.