Heap Buffer Overflow in mvfst by Facebook
CVE-2025-30403

8.1HIGH

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
11 July 2025

What is CVE-2025-30403?

A heap-buffer-overflow vulnerability exists in the mvfst library, which enables attackers to exploit the faulty handling of specially crafted messages during a QUIC session. This could potentially lead to security breaches or unauthorized actions in applications utilizing affected versions of mvfst. It is crucial for users of mvfst versions prior to v2025.07.07.00 to apply updates and secure their systems against this vulnerability.

Affected Version(s)

mvfst v2025.03.24.00

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-30403 : Heap Buffer Overflow in mvfst by Facebook