Facebook / Proxygen
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-91096 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) f… | HIGH | 7.5 | Sep 28, 2026 |
| CVE-2026-91095 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could ret… | MEDIUM | 5.3 | Sep 28, 2026 |
| CVE-2026-84895 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSes… | HIGH | 7.3 | Sep 28, 2026 |
| CVE-2026-44909 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-co… | HIGH | 7.5 | Jul 23, 2026 |
| CVE-2025-55181 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing ev… | MEDIUM | 5.3 | Dec 2, 2025 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2021-24029 | A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC sp… | HIGH | 7.5 | Mar 15, 2021 |
| CVE-2020-1897 | A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific… | CRITICAL | 9.8 | May 18, 2020 |
| CVE-2019-11940 | In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corr… | CRITICAL | 9.8 | Dec 4, 2019 |
| CVE-2019-11921 | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malform… | CRITICAL | 9.8 | Jul 25, 2019 |
| CVE-2018-6347 | An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | HIGH | 7.5 | Dec 31, 2018 |
| CVE-2018-6346 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen pri… | HIGH | 7.5 | Dec 31, 2018 |
| CVE-2018-6343 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/Ce… | HIGH | 7.5 | Dec 31, 2018 |
Showing 1 to 11 of 11 CVEs