Junglewise Threat Intelligence

CVE-2026-28975: Apple swift-nio-extras decompression ratio limit bypass in NIOHTTPRequestDecompressor

CVE-2026-28975 · Severity: medium · CVSS 6.9 · Published 2026-06-12

Vendors: Apple, Swift.

Executive brief

A vulnerability in the Swift NIO Extras library allows attackers to bypass security limits designed to prevent 'zip bomb' attacks. By providing a fake size value in a web request, an attacker can force the server to decompress massive amounts of data, potentially crashing the service or exhausting its memory. This can lead to a denial-of-service (DoS) condition where the application becomes unavailable to legitimate users.

Technical details

The NIOHTTPRequestDecompressor component in swift-nio-extras fails to properly validate decompression ratios when configured with the .ratio(N) limit. The implementation relies on the attacker-controlled Content-Length header as the denominator for ratio calculations instead of the actual number of compressed bytes received. An attacker can exploit this by sending a highly compressed payload (gzip bomb) with an artificially inflated Content-Length header, causing the ratio check to always pass. This results in unbounded memory consumption during decompression. The vulnerability is fixed in version 1.34.1 by tracking actual received bytes.

Affected products

  • Apple swift-nio-extras < 1.34.1

Timeline

  • 2026-05-21: disclosed
  • 2026-06-12: advisory

References