/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2019-11939

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2019-11939

CGA ID

CGA-ccj3-f4c8-28h3

Severity

7.5

High

CVSS V3

Description

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

References

  • https://images.chainguard.dev/security/CGA-ccj3-f4c8-28h3

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs