CVE detail
CVE-2019-11924 — CVE-2019-11924
Published 2019-08-20 · Modified 2026-06-17 · Vendor facebook · Product fizz · Source nvd
HIGH
severity
CVSS-derived band
0.0240
EPSS probability
exploitation probability, 30d
83.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References