« Volver al listado

Facebook

Facebook Proxygen: vulnerabilidades y CVE

Facebook Proxygen tiene 10 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses4
Críticas3
Explotadas activamente1

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-91095Media (5.3)0.25%—28 sept 2026
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already…
CVE-2026-84895Alta (7.3)0.14%—28 sept 2026
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler,…
CVE-2026-44909Alta (7.5)0.57%—23 jul 2026
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or…
CVE-2025-55181Media (5.3)0.29%—2 dic 2025
Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector…
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2021-24029Alta (7.5)1.2%—15 mar 2021
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a…
CVE-2020-1897Crítica (9.8)1.1%—18 may 2020
A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to…
CVE-2019-11940Crítica (9.8)1.4%—4 dic 2019
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and…
CVE-2019-11921Crítica (9.8)2.1%—25 jul 2019
An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue…
CVE-2018-6343Alta (7.5)0.83%—31 dic 2018
Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3)…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application4
  2. T1499.004 Application or System Exploitation2
  3. T1499 Endpoint Denial of Service1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Facebook