Denial of Service Vulnerability in Facebook Thrift by Facebook
CVE-2019-11938
7.5HIGH
What is CVE-2019-11938?
A vulnerability in Facebook Thrift allows attackers to exploit the server's handling of messages with oversized container declarations. By sending short messages, malicious clients can trigger large memory allocations on the server, potentially leading to denial of service. This issue has been addressed in versions released after v2019.12.09.00, and it highlights the importance of input size validation to prevent resource exhaustion attacks.
Affected Version(s)
Facebook Thrift < unspecified
Facebook Thrift v2019.12.09.00