PT-2026-64025 · Facebook · Proxygen

CVE-2026-44909

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Proxygen versions v2017.01.16.00 through v2026.07.20.00
Description The core HTTP session layer lacks a generalized slow-consumer detection mechanism. A remote, unauthenticated attacker can exploit HTTP/2 flow-control by setting SETTINGS INITIAL WINDOW SIZE to 0 or withholding WINDOW UPDATE frames. This forces the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening numerous simultaneous streams for large resources and preventing response transmission, an attacker can cause unbounded memory growth, resulting in resource exhaustion, service degradation, or denial of service.
Recommendations Update Proxygen to a version later than v2026.07.20.00.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-44909

Affected Products

Proxygen