NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
History

Mon, 03 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read in Swift NIO SSL Certificate Processing

Sun, 02 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read in Swift NIO SSL Certificate Processing

Sat, 01 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Read in Swift NIO SSL Certificate SAN Access

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple swiftnio Ssl
Vendors & Products Apple
Apple swiftnio Ssl

Mon, 27 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bound Read in Swift NIO SSL Certificate SAN Access

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2026-07-23T14:33:20.551Z

Updated: 2026-07-24T20:09:49.866Z

Reserved: 2026-05-01T22:46:27.822Z

Link: CVE-2026-43820

cve-icon Vulnrichment

Updated: 2026-07-24T20:09:00.928Z

cve-icon NVD

No data.

cve-icon Redhat

No data.