Skip to content

4.84.2 - [SECURITY] Incorrect request error handling triggers server crash

Compare
Choose a tag to compare
@gwynne gwynne released this 05 Oct 11:21
· 51 commits to main since this release
090464a

⚠️ Security Update ⚠️

This release fixes an issue introduced in 4.83.2 Vapor incorrectly handles errors encountered during parsing of HTTP 1.x requests, making it vulnerable to a Denial of Service attack. For more details see the security advisory GHSA-qvxg-wjxc-r4gg.

This vulnerability has been designated as CVE-2023-44386. Thank you to t0rchwood for reporting!