Junglewise Threat Intelligence

CVE-2026-65370: Apple ServiceTalk HTTP/1.x request smuggling via malformed Transfer-Encoding

CVE-2026-65370 · Severity: high · CVSS 7.5 · Published 2026-08-12

Vendors: Apple.

Executive brief

ServiceTalk is a networking framework used to build high-performance HTTP services. Due to improper validation of the Transfer-Encoding header, attackers can craft malformed requests that cause the HTTP/1.x parser to misinterpret message boundaries, allowing injection of unauthorized HTTP requests. This can lead to bypass of security controls, cache poisoning, or unauthorized access to backend services.

Technical details

The vulnerability exists in ServiceTalk's HttpObjectDecoder.readHeaders method, which fails to properly validate Transfer-Encoding headers according to RFC 9112 section 6.1. Specifically, the parser accepts Transfer-Encoding on non-HTTP/1.1 messages, treats chunked-encoded lists where chunked is not the final coding as valid, and processes messages with both Transfer-Encoding and Content-Length without closing the connection as required. This inconsistent header parsing enables HTTP request smuggling attacks where an attacker can inject hidden requests that are interpreted differently by intermediaries and backend servers. The vulnerability requires only network access and no authentication; it affects the confidentiality and integrity of transmitted data. The issue is patched in ServiceTalk version 0.42.65.

Affected products

  • Apple ServiceTalk < 0.42.65

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: Fixed in ServiceTalk version 0.42.65

References