CVE-2018-6335

HIGH

Facebook Hhvm < 3.21.10 - Denial of Service

Title source: rule
STIX 2.1

Description

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0069
EPSS Percentile 72.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-400
Status published
Products (3)
facebook/hhvm 3.24.6
facebook/hhvm 3.25.2
facebook/hhvm < 3.21.10
Published Dec 31, 2018
Tracked Since Feb 18, 2026