High
Apple SwiftNIO HTTP/2 is vulnerable to a denial of service, caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame. By sending a specially-crafted HTTP/2 frame, a remote attacker could exploit this vulnerability to cause the entire process to crash.
Upgrade to the latest version of SwiftNIO HTTP/2, available from the swift-nio-http2 GIT Repository.