Proxygen
Vendor:
First CVE: Dec 31, 2018 · Active for 7 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
10.0%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Proxygen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2018
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
CVE Severity & Scoring
Proxygen10 CVEs
10%
60%
30%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-44909HIGH Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETT | Jul 23, 2026 | 7.5 | 33 | NO | NO |
CVE-2019-11921CRITICAL An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in | Jul 25, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-11940CRITICAL In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations can place the header table into a corrupted state, leading | Dec 4, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-6343HIGH Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP | Dec 31, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-24029HIGH A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this par | Mar 15, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-1897CRITICAL A use-after-free is possible due to an error in lifetime management in the request adaptor when a malicious client invokes request error handling in a specific sequence. This issue | May 18, 2020 | 9.8 | 24 | NO | NO |
CVE-2018-6347HIGH An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | Dec 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-6346HIGH A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00. | Dec 31, 2018 | 7.5 | 24 | NO | NO |
CVE-2025-55181MEDIUM Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and uncondit | Dec 2, 2025 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
1 CVE
10.0% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Proxygen
Top CWEs
Versions
No cataloged versions.