CVE-2025-30403: Facebook Mvfst
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.
Affected products
- Facebook Mvfst: from v2025.03.24.00, before v2025.07.07.00 (fixed in v2025.07.07.00)
Published 2025-07-11. Last modified 2026-06-17.