CVE-2019-11940
CVE-2019-11940
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
04 Dec 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading to a use-after-free condition and undefined behavior. This issue affects Proxygen from v0.29.0 until v2017.04.03.00.
Affected products
Facebook · ProxygenWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →