CVE-2026-43798: Swift-nio-ssh swift-nio-ssh vulnerability
Published Aug 20, 2026
·Updated
A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.
Affected Software
1 affected component
swift-nio-ssh swift-nio-ssh
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
swift-nio-sshto a version that resolves this vulnerability.Fixed in 0.14.1
Event History
Aug 20, 2026
CVE Published
via MITRE·09:07 PM
Data Sourced
via MITRE·09:07 PM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated network attacker can exploit it by sending a single crafted SSH message to an affected application built on swift-nio-ssh.
2
What version resolves the vulnerability?
The vulnerability is addressed in swift-nio-ssh version 0.14.1.