Facebook's vulnerability footprint concentrates in a focused set of infrastructure and runtime products—most notably the HHVM virtual machine, Hermes JavaScript engine, Thrift middleware, and Proxygen HTTP library—that power internal and external service delivery at scale. Though the product portfolio remains relatively narrow, these components sit deep in production stacks and reach significant prominence in the vulnerability landscape, and vulnerabilities affecting them skew strongly toward critical-severity outcomes. The exposure recurs persistently through memory-safety and deserialization weakness classes: out-of-bounds reads and writes, use-after-free conditions, buffer-boundary violations, and untrusted deserialization, reflecting the low-level performance and parsing demands of runtime systems and middleware. Defenders tracking these products should prioritize patching for the severity risk they carry; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Facebook over time
Signals from CVEs in this vendor scope (135 CVEs).
135 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55182CRITICAL A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-serve | Dec 3, 2025 | 10.0 | 99 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2025-55184HIGH A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the following pa | Dec 11, 2025 | 7.5 | 83 | NO | YES |
CVE-2025-55183MEDIUM An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.0 and 19.2.1, including the foll | Dec 11, 2025 | 5.3 | 68 | NO | NO |
CVE-2008-5711HIGH Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value. | Dec 24, 2008 | 9.3 | 59 | NO | YES |
CVE-2008-0660HIGH Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Face | Feb 8, 2008 | 9.3 | 58 | NO | YES |
CVE-2021-24040CRITICAL Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execu | Sep 10, 2021 | 9.8 | 52 | NO | YES |
CVE-2025-67779HIGH It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case. React Server Compo | Dec 12, 2025 | 7.5 | 50 | NO | NO |
CVE-2026-23864HIGH Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom | Jan 26, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-44909HIGH Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETT | Jul 23, 2026 | 7.5 | 33 | NO | NO |
Signals from CVEs in this vendor scope (135 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Facebook.
Media articles that mention a CVE ID that affects a product developed by Facebook — matched by CVE ID, not by vendor name.