VYPR
High severity7.5NVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026

CVE-2019-11939

CVE-2019-11939

Description

Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/facebook/fbthriftGo
< 0.31.1-0.20200311080807-483ed864d69f0.31.1-0.20200311080807-483ed864d69f

Affected products

25

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.