CVE-2019-11921 describes a critical out-of-bounds write vulnerability in Facebook's Proxygen library, affecting versions prior to v2019.07.22.00. This flaw arises from improper Base64 handling when parsing malformed binary content within Structured HTTP Headers, allowing an attacker to craft a special packet to trigger the vulnerability. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, enabling unauthenticated remote attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity. Despite its critical severity and significant community discussion (10 mentions), there is currently no evidence of active exploitation, nor are there publicly available Metasploit modules, Nuclei templates, or ExploitDB entries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< v2019.07.22.00CPE match | cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:* | ||
< 2019.07.22.00CPE matchmatch criteria | cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.