Filtered by vendor Facebook Subscriptions
Filtered by product Mvfst Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-30403 1 Facebook 1 Mvfst 2025-07-15 8.1 High
A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.
CVE-2021-24029 1 Facebook 2 Mvfst, Proxygen 2024-11-21 7.5 High
A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a crash via a failed assertion. Per QUIC specification, this particular message should be treated as a connection error. This issue affects mvfst versions prior to commit a67083ff4b8dcbb7ee2839da6338032030d712b0 and proxygen versions prior to v2021.03.15.00.