Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Meta ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been… | |
| Aplazada | Media (5.3) | 0.25% | — | Facebook ProxygenAI | 28/9/2026 | 30/9/2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of… | |
| Aplazada | Alta (7.3) | 0.19% | — | Facebook ProxygenAI | 28/9/2026 | 1/10/2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it. | |
| Aplazada | Alta (7.5) | 0.57% | — | Facebook ProxygenAI | 23/7/2026 | 23/7/2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory… | |
| Analizada | Media (5.3) | 0.29% | — | Facebook Proxygen | 2/12/2025 | 17/6/2026 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually causes the process to… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 1.2% | — | Facebook MvfstFacebook Proxygen | 15/3/2021 | 17/6/2026 | A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit… | |
| Modificada | Crítica (9.8) | 1.1% | — | Facebook Proxygen | 18/5/2020 | 17/6/2026 | A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue affects versions of proxygen prior to v2020.05.18.00. | |
| Modificada | Crítica (9.8) | 1.4% | — | Facebook Proxygen | 4/12/2019 | 17/6/2026 | In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00. | |
| Modificada | Crítica (9.8) | 2.1% | — | Facebook Proxygen | 25/7/2019 | 17/6/2026 | An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00. | |
| Modificada | Alta (7.5) | 1.4% | — | Proxygen Project Proxygen | 31/12/2018 | 17/6/2026 | An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | |
| Modificada | Alta (7.5) | 1.4% | — | Proxygen Project Proxygen | 31/12/2018 | 17/6/2026 | A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00. | |
| Modificada | Alta (7.5) | 0.83% | — | Facebook Proxygen | 31/12/2018 | 17/6/2026 | Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz (TLS 1.3) transport. This issue affects Proxygen releases starting from v2018.10.29.00 until the fix in v2018.11.19.00. | |
| Modificada | Alta (7.5) | 1.2% | — | Proxygen Project Proxygen | 10/4/2017 | 17/6/2026 | Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks. | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxygen Project Proxygen | 10/4/2017 | 17/6/2026 | The SPDY/2 codec in Facebook Proxygen before 2015-11-09 truncates a certain field to two bytes, which allows hijacking and injection attacks. | |
| Modificada | Alta (7.5) | 1.2% | — | Proxygen Project Proxygen | 10/4/2017 | 17/6/2026 | The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value. |