4.84.2 - [SECURITY] Incorrect request error handling triggers server crash
This release fixes an issue introduced in 4.83.2 Vapor incorrectly handles errors encountered during parsing of HTTP 1.x requests, making it vulnerable to a Denial of Service attack. For more details see the security advisory GHSA-qvxg-wjxc-r4gg.
This vulnerability has been designated as CVE-2023-44386
. Thank you to t0rchwood for reporting!