An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00.
{
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:proxygen_project:proxygen:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2018.12.31.00"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-6347.json"
"2026-04-11T21:33:04Z"
[
{
"source": "https://github.com/facebook/proxygen/commit/223e0aa6bc7590e86af1e917185a2e0efe160711",
"digest": {
"line_hashes": [
"236994584668808591873749314743685538711",
"287831864845955272482723458710880812214",
"292427305810534468853244674471508994986"
],
"threshold": 0.9
},
"target": {
"file": "proxygen/lib/http/session/test/HTTPSessionMocks.h"
},
"deprecated": false,
"id": "CVE-2018-6347-9f022266",
"signature_version": "v1",
"signature_type": "Line"
},
{
"source": "https://github.com/facebook/proxygen/commit/223e0aa6bc7590e86af1e917185a2e0efe160711",
"digest": {
"function_hash": "134446923922520451265126210642508516068",
"length": 856.0
},
"target": {
"file": "proxygen/lib/http/codec/HTTP2Codec.cpp",
"function": "HTTP2Codec::generateTrailers"
},
"deprecated": false,
"id": "CVE-2018-6347-d3085f97",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://github.com/facebook/proxygen/commit/223e0aa6bc7590e86af1e917185a2e0efe160711",
"digest": {
"function_hash": "89815727445389674095704150648972147750",
"length": 827.0
},
"target": {
"file": "proxygen/lib/http/codec/HTTP2Codec.cpp",
"function": "HTTP2Codec::checkNewStream"
},
"deprecated": false,
"id": "CVE-2018-6347-de6fbf3e",
"signature_version": "v1",
"signature_type": "Function"
},
{
"source": "https://github.com/facebook/proxygen/commit/223e0aa6bc7590e86af1e917185a2e0efe160711",
"digest": {
"line_hashes": [
"32485062120988571348754436959625851609",
"45393258413948763852272137480870716980",
"82511126764959023433973723011659798701",
"214671182153014458576823772625620524384",
"303287528376876535686496087813190539809",
"250034824232753198650164219143773005416",
"136594427481044664571705481915540189149",
"323341156114263285089586718342605616975"
],
"threshold": 0.9
},
"target": {
"file": "proxygen/lib/http/codec/HTTP2Codec.cpp"
},
"deprecated": false,
"id": "CVE-2018-6347-e1c11fd9",
"signature_version": "v1",
"signature_type": "Line"
}
]