CVE-2025-30403: Facebook Mvfst

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

Affected products

  • Facebook Mvfst: from v2025.03.24.00, before v2025.07.07.00 (fixed in v2025.07.07.00)

Published 2025-07-11. Last modified 2026-06-17.