Impact
A denial-of-service vulnerability due to improper input validation allows a remote attacker to crash the service via a malformed HTTP header.
Allows crashing the process with data coming from the network when used with, for example, an HTTP server. Most common way of using Swift W3C Trace Context is through Swift OTel.
Patches
5da9b14
Workarounds
Disable either Swift OTel or the code that extracts the trace information from an incoming header (such as a TracingMiddleware).
References
Swift W3C TraceContext 1.0.0-beta.5
Swift OTel 1.0.4
Impact
A denial-of-service vulnerability due to improper input validation allows a remote attacker to crash the service via a malformed HTTP header.
Allows crashing the process with data coming from the network when used with, for example, an HTTP server. Most common way of using Swift W3C Trace Context is through Swift OTel.
Patches
5da9b14
Workarounds
Disable either Swift OTel or the code that extracts the trace information from an incoming header (such as a
TracingMiddleware).References
Swift W3C TraceContext 1.0.0-beta.5
Swift OTel 1.0.4