CVE-2019-3557: Facebook Hhvm

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

Affected products

  • Facebook Hhvm: up to and including 3.27.4; from 3.28.0, up to and including 3.30.0

Published 2019-01-15. Last modified 2026-06-17.