{"schema_version":1,"title":"Swift package vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Swift packages: 1 in the last 7 days and 4 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-61695, was published on 23 September 2026. 2 packages have a page of their own.","url":"https://junglewise.ai/threats/vendors/swift","json_url":"https://junglewise.ai/threats/vendors/swift.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/swift","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":5,"all_time":18,"critical":5,"exploited":0,"last_7_days":1,"last_30_days":1,"last_90_days":4,"last_365_days":11},"latest":[{"cve":"CVE-2026-61695","cvss":7.5,"epss":0.0058,"slug":"cve-2026-61695-square-wire-swift-runtime-negative-length-in-skipgroup-denial-of","title":"Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoRe","severity":"high","exploited":false,"published_at":"2026-09-23T19:17:32.81+00:00","url":"https://junglewise.ai/threats/cve-2026-61695-square-wire-swift-runtime-negative-length-in-skipgroup-denial-of"},{"cve":"CVE-2026-64785","cvss":5.3,"epss":0.0014,"slug":"cve-2026-64785-apple-swiftnio-http-2-request-smuggling-via-header-validation","title":"Apple SwiftNIO HTTP/2 request smuggling via header validation bypass","severity":"medium","exploited":false,"published_at":"2026-07-23T20:17:21.44+00:00","url":"https://junglewise.ai/threats/cve-2026-64785-apple-swiftnio-http-2-request-smuggling-via-header-validation"},{"cve":"CVE-2026-47122","cvss":4.2,"slug":"cve-2026-47122-sparkle-missing-authentication-in-appinstaller-mach-service","title":"Sparkle missing authentication in AppInstaller Mach service connection","severity":"medium","exploited":false,"published_at":"2026-07-21T15:16:35.327+00:00","url":"https://junglewise.ai/threats/cve-2026-47122-sparkle-missing-authentication-in-appinstaller-mach-service"},{"cve":"CVE-2026-47121","cvss":6.1,"slug":"cve-2026-47121-sparkle-path-traversal-via-intermediate-symlinks-in-delta-updates","title":"Sparkle path traversal via intermediate symlinks in delta updates","severity":"medium","exploited":false,"published_at":"2026-07-21T14:16:34.387+00:00","url":"https://junglewise.ai/threats/cve-2026-47121-sparkle-path-traversal-via-intermediate-symlinks-in-delta-updates"},{"cve":"CVE-2026-28898","cvss":0,"slug":"cve-2026-28898-apple-swift-nio-http2-request-smuggling-in-http2tohttp1codec","title":"Apple swift-nio-http2 request smuggling in HTTP2ToHTTP1Codec","severity":"low","exploited":false,"published_at":"2026-06-25T19:16:36.977+00:00","url":"https://junglewise.ai/threats/cve-2026-28898-apple-swift-nio-http2-request-smuggling-in-http2tohttp1codec"},{"cve":"CVE-2026-28975","cvss":6.9,"slug":"cve-2026-28975-apple-swift-nio-extras-decompression-ratio-limit-bypass-in","title":"Apple swift-nio-extras decompression ratio limit bypass in NIOHTTPRequestDecompressor","severity":"medium","exploited":false,"published_at":"2026-06-12T15:08:04+00:00","url":"https://junglewise.ai/threats/cve-2026-28975-apple-swift-nio-extras-decompression-ratio-limit-bypass-in"},{"cve":"CVE-2026-28980","cvss":8.7,"slug":"cve-2026-28980-apple-swiftnio-uncontrolled-resource-consumption-in-httpdecoder","title":"Apple SwiftNIO uncontrolled resource consumption in HTTPDecoder","severity":"high","exploited":false,"published_at":"2026-06-12T15:07:53+00:00","url":"https://junglewise.ai/threats/cve-2026-28980-apple-swiftnio-uncontrolled-resource-consumption-in-httpdecoder"},{"cve":"CVE-2026-43671","cvss":8.3,"slug":"cve-2026-43671-apple-swiftnio-out-of-bounds-write-in-bytebuffer","title":"Apple SwiftNIO out-of-bounds write in ByteBuffer","severity":"high","exploited":false,"published_at":"2026-06-12T15:07:23+00:00","url":"https://junglewise.ai/threats/cve-2026-43671-apple-swiftnio-out-of-bounds-write-in-bytebuffer"},{"cve":"CVE-2026-28970","cvss":6.3,"slug":"cve-2026-28970-apple-swiftnio-crlf-injection-in-http-validator-handlers","title":"Apple SwiftNIO CRLF injection in HTTP validator handlers","severity":"medium","exploited":false,"published_at":"2026-06-12T15:07:01+00:00","url":"https://junglewise.ai/threats/cve-2026-28970-apple-swiftnio-crlf-injection-in-http-validator-handlers"},{"cvss":1.9,"slug":"apple-container-pf-rule-injection-in-container-system-dns-create-9afe0647","title":"Apple container pf rule injection in container system dns create","severity":"low","exploited":false,"published_at":"2026-05-07T01:43:31+00:00","url":"https://junglewise.ai/threats/apple-container-pf-rule-injection-in-container-system-dns-create-9afe0647"},{"cve":"CVE-2026-27120","cvss":6.1,"slug":"cve-2026-27120-leaf-kit-html-escaping-does-not-work-on-characters-that-are-part","title":"Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster","severity":"medium","exploited":false,"published_at":"2026-02-19T19:40:08+00:00","url":"https://junglewise.ai/threats/cve-2026-27120-leaf-kit-html-escaping-does-not-work-on-characters-that-are-part"},{"cve":"CVE-2025-54950","cvss":9.8,"epss":0.006,"slug":"cve-2025-54950-pytorch-executorch-out-of-bounds-read-in-model-loading","title":"PyTorch ExecuTorch out-of-bounds read in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54950-pytorch-executorch-out-of-bounds-read-in-model-loading"},{"cve":"CVE-2025-30404","cvss":9.8,"epss":0.006,"slug":"cve-2025-30404-pytorch-executorch-integer-overflow-in-model-loading","title":"PyTorch ExecuTorch integer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-30404-pytorch-executorch-integer-overflow-in-model-loading"},{"cve":"CVE-2025-30405","cvss":9.8,"epss":0.006,"slug":"cve-2025-30405-meta-executorch-integer-overflow-in-model-loading","title":"Meta ExecuTorch integer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-30405-meta-executorch-integer-overflow-in-model-loading"},{"cve":"CVE-2025-54949","cvss":9.8,"epss":0.0067,"slug":"cve-2025-54949-meta-executorch-heap-buffer-overflow-in-model-loading","title":"Meta ExecuTorch heap buffer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54949-meta-executorch-heap-buffer-overflow-in-model-loading"},{"cve":"CVE-2025-54951","cvss":9.8,"epss":0.0067,"slug":"cve-2025-54951-executorch-heap-based-buffer-overflow-in-model-loading","title":"ExecuTorch heap-based buffer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54951-executorch-heap-based-buffer-overflow-in-model-loading"},{"cve":"CVE-2025-30402","cvss":8.1,"epss":0.0036,"slug":"cve-2025-30402-pytorch-executorch-heap-based-buffer-overflow-in-method-loading","title":"PyTorch ExecuTorch heap-based buffer overflow in method loading","severity":"high","exploited":false,"published_at":"2025-07-11T18:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-30402-pytorch-executorch-heap-based-buffer-overflow-in-method-loading"},{"cve":"CVE-2024-27529","cvss":8.4,"epss":0.0026,"slug":"cve-2024-27529-wasm3-uncontrolled-memory-allocation-in-read-utf8","title":"Wasm3 uncontrolled memory allocation in Read_utf8","severity":"high","exploited":false,"published_at":"2024-11-09T00:30:42+00:00","url":"https://junglewise.ai/threats/cve-2024-27529-wasm3-uncontrolled-memory-allocation-in-read-utf8"}],"vendor":{"hub":true,"name":"Swift","slug":"swift","homepage":"https://www.swift.org/","ecosystem":"Swift","description":"A technology company that develops the Swift programming language and related ecosystem.","url":"https://junglewise.ai/threats/vendors/swift"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2025-54951","cvss":9.8,"epss":0.0067,"slug":"cve-2025-54951-executorch-heap-based-buffer-overflow-in-model-loading","title":"ExecuTorch heap-based buffer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54951-executorch-heap-based-buffer-overflow-in-model-loading"},{"cve":"CVE-2025-54949","cvss":9.8,"epss":0.0067,"slug":"cve-2025-54949-meta-executorch-heap-buffer-overflow-in-model-loading","title":"Meta ExecuTorch heap buffer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54949-meta-executorch-heap-buffer-overflow-in-model-loading"},{"cve":"CVE-2025-54950","cvss":9.8,"epss":0.006,"slug":"cve-2025-54950-pytorch-executorch-out-of-bounds-read-in-model-loading","title":"PyTorch ExecuTorch out-of-bounds read in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-54950-pytorch-executorch-out-of-bounds-read-in-model-loading"},{"cve":"CVE-2025-30404","cvss":9.8,"epss":0.006,"slug":"cve-2025-30404-pytorch-executorch-integer-overflow-in-model-loading","title":"PyTorch ExecuTorch integer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-30404-pytorch-executorch-integer-overflow-in-model-loading"},{"cve":"CVE-2025-30405","cvss":9.8,"epss":0.006,"slug":"cve-2025-30405-meta-executorch-integer-overflow-in-model-loading","title":"Meta ExecuTorch integer overflow in model loading","severity":"critical","exploited":false,"published_at":"2025-08-08T00:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-30405-meta-executorch-integer-overflow-in-model-loading"},{"cve":"CVE-2026-28980","cvss":8.7,"slug":"cve-2026-28980-apple-swiftnio-uncontrolled-resource-consumption-in-httpdecoder","title":"Apple SwiftNIO uncontrolled resource consumption in HTTPDecoder","severity":"high","exploited":false,"published_at":"2026-06-12T15:07:53+00:00","url":"https://junglewise.ai/threats/cve-2026-28980-apple-swiftnio-uncontrolled-resource-consumption-in-httpdecoder"},{"cve":"CVE-2024-27529","cvss":8.4,"epss":0.0026,"slug":"cve-2024-27529-wasm3-uncontrolled-memory-allocation-in-read-utf8","title":"Wasm3 uncontrolled memory allocation in Read_utf8","severity":"high","exploited":false,"published_at":"2024-11-09T00:30:42+00:00","url":"https://junglewise.ai/threats/cve-2024-27529-wasm3-uncontrolled-memory-allocation-in-read-utf8"},{"cve":"CVE-2026-43671","cvss":8.3,"slug":"cve-2026-43671-apple-swiftnio-out-of-bounds-write-in-bytebuffer","title":"Apple SwiftNIO out-of-bounds write in ByteBuffer","severity":"high","exploited":false,"published_at":"2026-06-12T15:07:23+00:00","url":"https://junglewise.ai/threats/cve-2026-43671-apple-swiftnio-out-of-bounds-write-in-bytebuffer"},{"cve":"CVE-2025-30402","cvss":8.1,"epss":0.0036,"slug":"cve-2025-30402-pytorch-executorch-heap-based-buffer-overflow-in-method-loading","title":"PyTorch ExecuTorch heap-based buffer overflow in method loading","severity":"high","exploited":false,"published_at":"2025-07-11T18:30:34+00:00","url":"https://junglewise.ai/threats/cve-2025-30402-pytorch-executorch-heap-based-buffer-overflow-in-method-loading"},{"cve":"CVE-2026-61695","cvss":7.5,"epss":0.0058,"slug":"cve-2026-61695-square-wire-swift-runtime-negative-length-in-skipgroup-denial-of","title":"Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoRe","severity":"high","exploited":false,"published_at":"2026-09-23T19:17:32.81+00:00","url":"https://junglewise.ai/threats/cve-2026-61695-square-wire-swift-runtime-negative-length-in-skipgroup-denial-of"}],"generated_at":"2026-09-26T10:14:00.201383+00:00","technologies":[{"name":"github.com/pytorch/executorch (Swift)","slug":"github-com-pytorch-executorch","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/github-com-pytorch-executorch"},{"name":"github.com/apple/swift-nio (Swift)","slug":"github-com-apple-swift-nio","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/github-com-apple-swift-nio"}]}