Home/Product/facebook proxygen
Product

facebook proxygen

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-55181
>= 2025.08.25.00 and <= 2025.12.01.00
Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSessio
5.3MEDIUM
CVE-2023-44487
< 2023.10.16.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5HIGH
CVE-2021-24029
< 2021.03.15.00
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a
7.5HIGH
CVE-2020-1897
< 2020.05.18.00
A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request
9.8CRITICAL
CVE-2019-11940
>= 0.29.0 and <= 2017.04.03.00
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place
9.8CRITICAL
CVE-2019-11921
< 2019.07.22.00
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling o
9.8CRITICAL
CVE-2018-6347
< 2018.12.31.00
An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxyg
7.5HIGH
CVE-2018-6346
< 2018.12.31.00
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependenc
7.5HIGH
CVE-2018-6343
>= 2018.10.29.00 and < 2018.11.19.00
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue
7.5HIGH
CVE-2015-7265
<= 0.32.0
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attac
7.5HIGH
CVE-2015-7264
<= 0.32.0
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injecti
9.8CRITICAL
CVE-2015-7263
<= 0.32.0
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin