{"id":"CVE-2026-43820","details":"NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.","aliases":["GHSA-xfxg-9975-pc2j"],"modified":"2026-09-06T08:07:53.695044Z","published":"2026-07-23T15:17:05.503Z","references":[{"type":"EVIDENCE","url":"https://github.com/apple/swift-nio-ssl/security/advisories/GHSA-xfxg-9975-pc2j"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apple/swift-nio-ssl","events":[{"introduced":"b5260a31c2a72a89fa684f5efb3054d8725a2316"},{"fixed":"d930168b86f46ca51a4bc09c5ca45c1833db8067"}],"database_specific":{"cpe":"cpe:2.3:a:apple:swiftnio_ssl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.18.0"},{"fixed":"2.37.2"}],"source":"CPE_RANGE"}}],"versions":["2.37.1","2.37.0","2.36.1","2.36.0","2.35.0","2.34.1","2.34.0","2.33.0","2.32.0","2.31.0","2.30.0","2.29.3","2.29.1","2.29.2","2.29.0","2.28.0","2.27.2","2.27.1","2.27.0","2.26.0","2.25.0","2.24.0","2.23.1","2.23.0","2.22.1","2.22.0","2.21.0","2.20.2","2.20.1","2.20.0","2.19.0","2.18.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43820.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}