Denial of Service Vulnerability in Facebook Thrift Legacy C++ Servers
CVE-2019-3565
What is CVE-2019-3565?
The vulnerability in Facebook Thrift affects legacy C++ servers using cpp instead of cpp2, allowing malicious clients to exploit the system. When these servers receive messages containing container fields of unknown type, they fail to generate an error response. This flaw enables an attacker to send short, malformed messages that prolong server parsing times, potentially leading to a disruption of service. The affected versions of Facebook Thrift should be updated to at least v2019.05.06.00 to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Facebook Thrift v2019.05.06.00
Facebook Thrift < unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
