Critical severity9.8NVD Advisory· Published Dec 4, 2019· Updated Jun 17, 2026
CVE-2019-11935
CVE-2019-11935
Description
Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*range: <3.30.12
- cpe:2.3:a:facebook:hhvm:4.24.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.25.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.26.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.27.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.28.0:*:*:*:*:*:*:*
- cpe:2.3:a:facebook:hhvm:4.28.1:*:*:*:*:*:*:*
- (no CPE)range: <3.30.12, 4.0.0-4.8.5, 4.9.0-4.23.1, 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, 4.28.1
- (no CPE)range: 4.28.2
Patches
Vulnerability mechanics
References
3- github.com/facebook/hhvm/commit/1c518555dba6ceb45d5ba61845b96e261219c3b7nvdPatchThird Party Advisory
- hhvm.com/blog/2019/10/28/security-update.htmlnvdVendor Advisory
- www.facebook.com/security/advisories/cve-2019-11935nvdVendor Advisory
News mentions
0No linked articles in our index yet.