LiveActive security incident?Get immediate response
CVE Record

CVE-2020-9861: A stack overflow issue existed in Swift for Linux.

A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2020-9861 is a Swift for Linux flaw where specially crafted, deeply nested JSON could cause stack exhaustion. For businesses, the main concern is service instability if Linux-based Swift applications parse untrusted JSON from users, partners, or internet-facing APIs.

Executive priority

Prioritize if Swift for Linux powers public APIs or partner-facing JSON ingestion. Otherwise, handle through normal dependency maintenance because exploitation evidence and severity details are incomplete in the provided sources.

Technical view

The CVE describes a stack overflow in Swift for Linux JSON parsing. The issue was addressed with improved input validation for deeply nested malicious JSON input. The source bundle does not provide CVSS, CWE, exact version ranges, or impact beyond the stack overflow condition.

Likely exposure

Exposure is most likely in Swift 5.1.5 for Linux environments or related Linux Swift applications that process attacker-controlled JSON. Systems that do not use Swift for Linux JSONSerialization, or only parse trusted JSON, are less likely exposed.

Exploitation context

The source bundle does not show CISA KEV listing or cited evidence of active exploitation. Exploitation would depend on a vulnerable Swift for Linux JSON parser receiving deeply nested malicious JSON input.

Researcher notes

Evidence is sparse: no CVSS vector, CWE, exploit status, or precise vulnerable version range is provided. The strongest technical signal is vendor-described input validation for deeply nested JSON causing stack overflow.

Mitigation direction

  • Check Swift vendor guidance for the fixed Linux build or version range.
  • Upgrade affected Swift for Linux runtimes and build images where applicable.
  • Restrict untrusted JSON input size and nesting depth at application boundaries.
  • Add safe failure handling for malformed or excessive JSON input.

Validation and detection

  • Inventory Linux services built with Swift and JSONSerialization usage.
  • Confirm deployed Swift versions against vendor advisory information.
  • Review public API endpoints that accept JSON from untrusted users.
  • Test in staging that excessive nesting is rejected without crashing.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-9861 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
SwiftSwift 5.1.5 for LinuxunspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.