Vapor · Vapor · CVE-2026-43678
**Name of the Vulnerable Software and Affected Versions**
swift-nio versions prior to 2.101.0
**Description**
An unauthenticated remote peer can cause a crash in any NIOWebSocket-based server, such as Vapor and Hummingbird. This occurs when a single 11-byte frame is sent following a completed WebSocket handshake, resulting in the termination of all active connections until the process is restarted.
**Recommendations**
Update swift-nio to version 2.101.0.