Excessive Iteration Affecting facebook/proxygen package, versions [2025.08.25.00,2025.12.02.00)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-FACEBOOKPROXYGEN-14172375
  • published3 Dec 2025
  • disclosed2 Dec 2025
  • creditUnknown

Introduced: 2 Dec 2025

NewCVE-2025-55181  (opens in a new tab)
CWE-834  (opens in a new tab)

How to fix?

Upgrade facebook/proxygen to version 2025.12.02.00 or higher.

Overview

Affected versions of this package are vulnerable to Excessive Iteration in the proxygen::coro::HTTPQuicCoroSession() function. An attacker can cause unbounded memory growth and exhaust system resources by sending an HTTP request or response body larger than 2^31 bytes, which triggers an infinite loop that blocks the event loop and continuously appends data to memory.

CVSS Base Scores

version 4.0
version 3.1