CVE-2023-44386
Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections when HTTP parse errors occur instead of passing them on. The issue is fixed as of Vapor release 4.84.2.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.05%
- CWE
- CWE-231, CWE-617, CWE-696
- Published
- 2023-10-05
- Last modified
- 2026-03-13
Affected products
- vapor vapor
Weakness type
Related vulnerabilities
- CVE-2026-22888 — Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to...
- CVE-2024-20268 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Denial of Service Vulnerability
- CVE-2023-6841 — Keycloak: amount of attributes per object is not limited and it may lead to dos