CVE-2016-6872: Facebook Hhvm

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

Affected products

  • Facebook Hhvm: up to and including 3.14.5

Published 2017-02-17. Last modified 2026-06-17.