Skip to main content

Vendor/product archive

facebook / proxygen CVEs

Beta · best-effort

6 CVEs tagged to facebook / proxygen3 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2025-55181

Published Dec 2, 2025

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and uncondi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24029

Published Mar 15, 2021

A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1897

Published May 18, 2020

A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11940

Published Dec 4, 2019

In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11921

Published Jul 25, 2019

An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6343

Published Dec 31, 2018

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1