PT-2026-64025 · Facebook · Proxygen
CVE-2026-44909
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Proxygen versions v2017.01.16.00 through v2026.07.20.00
Description
The core HTTP session layer lacks a generalized slow-consumer detection mechanism. A remote, unauthenticated attacker can exploit HTTP/2 flow-control by setting
SETTINGS INITIAL WINDOW SIZE to 0 or withholding WINDOW UPDATE frames. This forces the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening numerous simultaneous streams for large resources and preventing response transmission, an attacker can cause unbounded memory growth, resulting in resource exhaustion, service degradation, or denial of service.Recommendations
Update Proxygen to a version later than v2026.07.20.00.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Proxygen