Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1891 | Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network. |
Github GHSA |
GHSA-vj2m-9f5j-mpr5 | Vapor vulnerable to denial of service in HTTP Range Request of FileMiddleware |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T17:55:35.387Z
Reserved: 2022-05-18T00:00:00.000Z
Link: CVE-2022-31005
No data.
Status : Modified
Published: 2022-05-31T20:15:07.973
Modified: 2024-11-21T07:03:41.977
Link: CVE-2022-31005
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA