CVE-2026-44909: CWE-770 in Facebook proxygen
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.
AI Analysis
Technical Summary
CVE-2026-44909 is a vulnerability in Facebook's proxygen HTTP library where the core HTTP/2 session layer does not detect slow consumers. An attacker can exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to zero or withholding WINDOW_UPDATE frames, causing the server to buffer entire response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams with large resource requests and preventing the server from sending responses, the attacker can induce unbounded memory growth, resulting in resource exhaustion and denial of service. This affects versions from 2017.01.16.00 through 2026.07.20.00.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause unbounded memory growth on the server by exploiting HTTP/2 flow-control mechanisms. This can lead to service degradation, resource exhaustion, or denial of service conditions. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation is currently documented. Until a patch is available, consider limiting HTTP/2 connections or monitoring for abnormal resource usage related to stalled streams.
CVE-2026-44909: CWE-770 in Facebook proxygen
Description
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/facebook/proxygenRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44909 is a vulnerability in Facebook's proxygen HTTP library where the core HTTP/2 session layer does not detect slow consumers. An attacker can exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to zero or withholding WINDOW_UPDATE frames, causing the server to buffer entire response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams with large resource requests and preventing the server from sending responses, the attacker can induce unbounded memory growth, resulting in resource exhaustion and denial of service. This affects versions from 2017.01.16.00 through 2026.07.20.00.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause unbounded memory growth on the server by exploiting HTTP/2 flow-control mechanisms. This can lead to service degradation, resource exhaustion, or denial of service conditions. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation is currently documented. Until a patch is available, consider limiting HTTP/2 connections or monitoring for abnormal resource usage related to stalled streams.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Meta
- Date Reserved
- 2026-05-08T02:33:35.450Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6246fe9c2644c7f8644e6b
Added to database: 07/23/2026, 16:53:18 UTC
Last enriched: 07/23/2026, 17:07:31 UTC
Last updated: 07/24/2026, 00:50:27 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.