{"id":"CVE-2019-3563","details":"Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a potential underflow. This affects versions of Wangle prior to v2019.04.22.00","modified":"2026-07-08T16:08:29.471035Z","published":"2019-04-29T16:29:01.047Z","references":[{"type":"FIX","url":"https://github.com/facebook/wangle/commit/5b3bceca875e4ea4ed9d14c20b20ce46c92c13c6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/wangle","events":[{"introduced":"0"},{"fixed":"52ac74a45aebafc28e4a0b7ab3ae529a914d9ecf"},{"fixed":"5b3bceca875e4ea4ed9d14c20b20ce46c92c13c6"}],"database_specific":{"cpe":"cpe:2.3:a:facebook:wangle:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2019.04.22.00"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2019.04.15.00","v2019.04.08.00","v2019.04.01.00","v2019.03.25.00","v2019.03.18.00","v2019.03.04.00","v2019.02.25.00","v2019.02.18.00","v2019.02.11.00","v2019.02.04.00","v2019.01.28.00","v2019.01.21.00","v2019.01.14.00","v2019.01.07.00","v2018.12.31.00","v2018.12.24.00","v2018.12.17.00","v2018.12.10.00","v2018.12.03.00","v2018.11.26.00","v2018.11.19.00","v2018.11.12.00","v2018.11.05.00","v2018.10.29.00","v2018.10.22.00","v2018.10.15.00","v2018.10.08.00","v2018.10.01.00","v2018.09.24.00","v2018.09.17.00","v2018.09.10.00","v2018.09.03.00","v2018.08.27.00","v2018.08.20.00","v2018.08.13.00","v2018.08.06.00","v2018.07.30.00","v2018.07.23.00","v2018.07.16.00","v2018.07.09.00","v2018.07.02.00","v2018.06.25.00","v2018.06.04.00","v2018.05.28.00","v2018.05.21.00","v2018.05.14.00","v2018.05.07.00","v2018.04.30.00","v2018.04.23.00","v2018.04.09.00","v2018.04.02.00","v2018.03.26.00","v2018.03.19.00","v2018.03.12.00","v2018.03.05.00","v2018.02.26.00","v2018.02.19.00","v2018.02.12.00","v2018.02.05.00","v2018.01.29.00","v2018.01.22.00","v2018.01.15.00","v2018.01.08.00","v2018.01.01.00","v2017.12.25.00","v2017.12.18.00","v2017.12.11.00","v2017.12.04.00","v2017.11.27.00","v2017.11.20.00","v2017.11.13.00","v2017.11.06.00","v2017.10.30.00","v2017.10.23.00","v2017.10.16.00","v2017.10.09.00","v2017.10.02.00","v2017.09.25.00","v2017.09.18.00","v2017.09.11.00","v2017.09.04.00","v2017.08.21.00","v2017.08.14.00","v2017.08.07.00","v2017.07.31.00","v2017.07.24.00","v2017.07.17.00","v2017.07.10.00","v2017.07.03.00","v2017.06.26.00","v2017.06.19.00","v2017.06.12.00","v2017.06.05.00","v2017.05.29.00","v2017.05.22.00","v2017.05.15.00","v2017.05.08.00","v2017.05.01.00","v2017.04.24.00","v2017.04.17.00","v2017.04.10.00","v2017.04.03.00","v2017.03.27.00","v2017.03.20.00","v2017.03.13.00","v2017.03.06.00","v2017.01.30.00","v2017.01.23.00","v2017.01.16.00","v2017.01.09.00","v2017.01.02.00","v2016.12.26.00","v2016.12.19.00","v2016.12.12.00","v2016.12.05.00","v2016.11.28.00","v2016.11.21.00","v2016.11.14.00","v2016.11.07.00","v2016.10.31.00","v2016.10.24.00","v2016.10.17.00","v2016.10.10.00","v2016.10.03.00","v2016.09.26.00","v0.13.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0"],"database_specific":{"vanir_signatures":[{"id":"CVE-2019-3563-5754e038","signature_type":"Function","signature_version":"v1","source":"https://github.com/facebook/wangle/commit/5b3bceca875e4ea4ed9d14c20b20ce46c92c13c6","target":{"file":"wangle/codec/LineBasedFrameDecoder.cpp","function":"LineBasedFrameDecoder::findEndOfLine"},"deprecated":false,"digest":{"function_hash":"209862306761955283688617153797711746561","length":470}},{"deprecated":false,"digest":{"line_hashes":["316347404982441586342694971964138432228","254508300517914634922767480531295796323","100883644009589782239601712373265476115","128216839699839833564535232473458388033","316519487855829563408192699816869100194"],"threshold":0.9},"id":"CVE-2019-3563-933456d1","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/wangle/commit/5b3bceca875e4ea4ed9d14c20b20ce46c92c13c6","target":{"file":"wangle/codec/LineBasedFrameDecoder.cpp"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3563.json","vanir_signatures_modified":"2026-07-08T16:08:29Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}