{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-21T13:40:27.849","vulnerabilities":[{"cve":{"id":"CVE-2019-3558","sourceIdentifier":"cve-assign@fb.com","published":"2019-05-06T16:29:00.990","lastModified":"2026-06-17T02:35:13.637","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00."},{"lang":"es","value":"Los servidores Python de Facebook Thrift no cometerían errores al recibir mensajes con titúlares de campos de tipo desconocido. Como resultado, los clientes maliciosos podrían enviar mensajes cortos, lo que llevaría mucho tiempo de análisis por parte del servidor, lo que podría llevar a una Denegación de Servicio (DoS). Este problema afecta a Facebook Thrift anterior a la versión v2019.02.18.00."}],"affected":[{"source":"cve-assign@fb.com","affectedData":[{"vendor":"Facebook","product":"Facebook Thrift","versions":[{"version":"v2019.02.18.00","status":"affected"},{"version":"unspecified","lessThan":"v2019.02.18.00","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cve-assign@fb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-834"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-755"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:facebook:thrift:*:*:*:*:*:*:*:*","versionEndExcluding":"2019.02.18.00","matchCriteriaId":"97E99CF8-B44E-4EC9-88CB-A7F8D186F951"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/108274","source":"cve-assign@fb.com","tags":["Broken Link"]},{"url":"https://github.com/facebook/fbthrift/commit/c5d6e07588cd03061bc54d451a7fa6e84883d62b","source":"cve-assign@fb.com","tags":["Patch","Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E","source":"cve-assign@fb.com"},{"url":"https://www.facebook.com/security/advisories/cve-2019-3558","source":"cve-assign@fb.com","tags":["Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/108274","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://github.com/facebook/fbthrift/commit/c5d6e07588cd03061bc54d451a7fa6e84883d62b","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.facebook.com/security/advisories/cve-2019-3558","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}