← back
CVE-2019-11940

CVE-2019-11940

EPSS 1.4%CWE-416
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
04 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.
Affected products
Facebook · Proxygen

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →