GHSA-h27g-g76x-xqpw
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.