CVE-2026-65370 PUBLISHED

Assigner: apple
Reserved: 22.07.2026 Published: 12.08.2026 Updated: 13.08.2026

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.

Product Status

Vendor Apple
Product servicetalk
Versions
  • affected from 0 to 0.42.65 (excl.)

References

Problem Types

  • ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks.