VYPR
Medium severity5.3NVD Advisory· Published Dec 2, 2025· Updated Jun 17, 2026

CVE-2025-55181

CVE-2025-55181

Description

Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuicCoroSession which blocks the backing event loop and unconditionally appends data to a std::vector per-loop iteration. This issue leads to unbounded memory growth and eventually causes the process to run out of memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Facebook/Proxygencpe-rescue3 versions
    v2025.08.25.00+ 2 more
    • (no CPE)range: v2025.08.25.00
    • (no CPE)
    • cpe:2.3:a:facebook:proxygen:*:*:*:*:*:*:*:*range: >=2025.08.25.00,<=2025.12.01.00

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.