Description
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/facebook/proxygen/commit/2f07985bef9fbae124cc63e5c0272e32da4fdaec
Third Party Advisory x_refsource_confirm
https://www.facebook.com/security/advisories/cve-2019-11921
Scores
CVSS v3
9.8
EPSS
0.0208
EPSS Percentile
79.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-787
Status
published
Products (1)
facebook/proxygen
< 2019.07.22.00
Published
Jul 25, 2019
Tracked Since
Feb 18, 2026