CVE-2022-31005
Dashboard / Vulnerabilities / CVE-2022-31005
Summary: Integer Overflow in Vapor's HTTP Range Request
Details: Vapor is an HTTP web framework for Swift. Users of Vapor prior to version 4.60.3 with FileMiddleware enabled are vulnerable to an integer overflow vulnerability that can crash the application. Version 4.60.3 contains a patch for this issue. As a workaround, disable FileMiddleware and serve via a Content Delivery Network.
References: https://github.com/vapor/vapor/releases/tag/4.60.3, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31005.json, https://github.com/vapor/vapor/security/advisories/GHSA-vj2m-9f5j-mpr5, https://nvd.nist.gov/vuln/detail/CVE-2022-31005, https://github.com/vapor/vapor/commit/953a349b539b3e0d3653585c8ffb50c427986df1
Affected packages
Package
Name:
Purl:
