CVE-2026-84895
- EPSS 0.15%
- Veröffentlicht 28.09.2026 21:17:19
- Zuletzt bearbeitet 01.10.2026 15:17:32
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last refer...
CVE-2026-91095
- EPSS 0.15%
- Veröffentlicht 28.09.2026 21:17:19
- Zuletzt bearbeitet 30.09.2026 20:17:36
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed thos...
CVE-2026-91096
- EPSS 0.15%
- Veröffentlicht 28.09.2026 21:17:19
- Zuletzt bearbeitet 30.09.2026 20:17:36
In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying t...
CVE-2026-44909
- EPSS 0.52%
- Veröffentlicht 23.07.2026 16:27:01
- Zuletzt bearbeitet 23.07.2026 20:17:08
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, cau...
CVE-2025-55181
- EPSS 0.29%
- Veröffentlicht 02.12.2025 22:16:08
- Zuletzt bearbeitet 19.12.2025 18:02:26
Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue l...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-24029
- EPSS 1.19%
- Veröffentlicht 15.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:14
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue af...
CVE-2020-1897
- EPSS 1.15%
- Veröffentlicht 18.05.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:34
A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to v2020.05.18.00.
CVE-2019-11940
- EPSS 1.36%
- Veröffentlicht 04.12.2019 17:16:43
- Zuletzt bearbeitet 21.11.2024 04:22:01
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affec...
CVE-2019-11921
- EPSS 2.08%
- Veröffentlicht 25.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:59
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior...