Skip to main content

Vendor archive

facebook CVEs

Beta · best-effort

126 CVEs tagged to vendor facebook57 Critical, 50 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2026-23864

Published Jan 26, 2026

Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-do…

CVSS 7.5 · High
evidence mentions
9
Buzz score
41.0
Vendor/product tagsBeta · best-effort

CVE-2025-67779

Published Dec 12, 2025

It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Comp…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55184

Published Dec 11, 2025

A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following p…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55183

Published Dec 11, 2025

An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the fol…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55182

Published Dec 3, 2025

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serv…

CVSS 10.0 · Critical
evidence mentions
49
Buzz score
93.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55181

Published Dec 2, 2025

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and uncondi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27591

Published Mar 11, 2025

A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed loca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23347

Published Jan 16, 2024

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49062

Published Nov 28, 2023

Katran could disclose non-initialized kernel memory as part of an IP header. The issue was present for IPv4 encapsulation and ICMP (v4) Too Big packet generation. After a bpf_xdp_…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5654

Published Oct 19, 2023

The React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45239

Published Oct 6, 2023

A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30470

Published May 18, 2023

A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could h…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28753

Published May 18, 2023

netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption wit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-28081

Published May 18, 2023

A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-25933

Published May 18, 2023

A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted Ja…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24833

Published May 18, 2023

A use-after-free in BigIntPrimitive addition in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by an attacker to leak raw data from Hermes VM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24832

Published May 18, 2023

A null pointer dereference bug in Hermes prior to commit 5cae9f72975cf0e5a62b27fdd8b01f103e198708 could have been used by an attacker to crash an Hermes runtime where the EnableHe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23759

Published May 18, 2023

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23557

Published May 18, 2023

An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23556

Published May 18, 2023

An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code d…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36937

Published May 10, 2023

HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is depr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30792

Published Apr 29, 2023

Anchor tag hrefs in Lexical prior to v0.10.0 would render javascript: URLs, allowing for cross-site scripting on link clicks in cases where input was being parsed from untrusted s…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4899

Published Mar 31, 2023

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36938

Published Nov 11, 2022

DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40138

Published Oct 11, 2022

An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and s…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 126 CVEsPage 1 of 6