A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apple:swiftnio_ssh:*:*:*:*:*:swift:*:* |
Wed, 26 Aug 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stack Out‑of‑Bounds Write via Crafted SSH Message in Swift‑NIO‑SSH |
Wed, 26 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
cvssV3_1
|
Fri, 21 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple swiftnio Ssh |
|
| Vendors & Products |
Apple
Apple swiftnio Ssh |
Fri, 21 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stack Out‑of‑Bounds Write via Crafted SSH Message in Swift‑NIO‑SSH | |
| Weaknesses | CWE-119 CWE-122 |
Thu, 20 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2026-08-20T21:07:01.719Z
Updated: 2026-08-26T14:05:32.813Z
Reserved: 2026-05-01T22:46:27.820Z
Link: CVE-2026-43798
Updated: 2026-08-26T14:05:25.562Z
Status : Analyzed
Published: 2026-08-20T21:17:06.580
Modified: 2026-09-03T13:35:56.153
Link: CVE-2026-43798
No data.