Skip to main content

Vendor archive

vapor CVEs

Beta · best-effort

8 CVEs tagged to vendor vapor0 Critical, 3 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-28499

Published Mar 18, 2026

LeafKit is a templating language with Swift-inspired syntax. Prior to version 1.14.2, HTML escaping doesn't work correctly when a template prints a collection (Array / Dictionary)…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-27120

Published Feb 20, 2026

Leafkit is a templating language with Swift-inspired syntax. Prior to 1.4.1, htmlEscaped in leaf-kit will only escape html special characters if the extended grapheme clusters mat…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-21631

Published Jan 3, 2024

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44386

Published Oct 5, 2023

Vapor is an HTTP web framework for Swift. There is a denial of service vulnerability impacting all users of affected versions of Vapor. The HTTP1 error handler closed connections…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31136

Published May 9, 2023

PostgresNIO is a Swift client for PostgreSQL. Any user of PostgresNIO prior to version 1.14.2 connecting to servers with TLS enabled is vulnerable to a man-in-the-middle attacker…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31019

Published Jun 9, 2022

Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following reque…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31005

Published May 31, 2022

Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37634

Published Aug 9, 2021

Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scripting (XSS) attacks. This affects anyone passing unsanitised…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1