CVE-2019-11921: Facebook Proxygen

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An out of bounds write is possible via a specially crafted packet in certain configurations of Proxygen due to improper handling of Base64 when parsing malformed binary content in Structured HTTP Headers. This issue affects versions of proxygen prior to v2019.07.22.00.

Affected products

  • Facebook Proxygen: before 2019.07.22.00 (fixed in 2019.07.22.00)

Published 2019-07-25. Last modified 2026-06-17.