{"id":"CVE-2021-24044","details":"By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.","aliases":["GHSA-7mhc-prgv-r3q4"],"modified":"2026-07-09T05:13:43.671775Z","published":"2022-01-15T01:15:07.943Z","references":[{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2021-24044"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/hermes","events":[{"introduced":"0"},{"fixed":"98f5028619294b6b14cddf5903a0f831d0edef9c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.10.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:*"}}],"versions":["v0.9.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.1","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-24044.json","vanir_signatures_modified":"2026-07-09T05:13:43Z","vanir_signatures":[{"id":"CVE-2021-24044-2abf4027","signature_type":"Function","signature_version":"v1","source":"https://github.com/facebook/hermes/commit/98f5028619294b6b14cddf5903a0f831d0edef9c","target":{"function":"createObjectConstructor","file":"lib/VM/JSLib/Object.cpp"},"deprecated":false,"digest":{"length":4517,"function_hash":"28119057494351730174264949473428385543"}},{"signature_version":"v1","source":"https://github.com/facebook/hermes/commit/98f5028619294b6b14cddf5903a0f831d0edef9c","target":{"file":"lib/VM/JSLib/Object.cpp"},"deprecated":false,"digest":{"line_hashes":["156164893267926276119498081931587824656","130702755843183064893722258247476490947","187778433998099261786328089378702710635","325593157944680459102889579367643710387"],"threshold":0.9},"id":"CVE-2021-24044-3fe77b4f","signature_type":"Line"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}