CVE-2019-3561: Facebook Hhvm

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects all supported versions of HHVM (4.0.3, 3.30.4, and 3.27.7 and below).

Affected products

  • Facebook Hhvm: up to and including 3.27.7; from 3.28.0, up to and including 3.30.4; from 4.0.0, up to and including 4.0.3

Published 2019-04-29. Last modified 2026-06-17.