{"id":"CVE-2025-30403","details":"A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.","modified":"2026-08-12T14:52:36.283320Z","published":"2025-07-11T18:26:51.212Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30403.json","cna_assigner":"facebook"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30403.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30403"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2025-30403"},{"type":"FIX","url":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/mvfst","events":[{"introduced":"04a27a3abe1a3d3007957cefaa33f1a857aa9bbd"},{"fixed":"65b297332191de6e867c4a3139a233fc84c0e7e0"}],"database_specific":{"extracted_events":[{"introduced":"v2025.03.24.00"},{"fixed":"v2025.07.07.00"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2025.06.30.00","v2025.06.23.00","v2025.06.16.00","v2025.06.09.00","v2025.06.02.00","v2025.05.26.00","v2025.05.19.00","v2025.05.12.00","v2025.05.05.00","v2025.04.28.00","v2025.04.21.00","v2025.04.14.00","v2025.04.07.00","v2025.03.31.00","v2025.03.24.00"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30403.json","vanir_signatures_modified":"2026-08-12T14:52:36Z","vanir_signatures":[{"source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0","target":{"file":"quic/server/test/QuicServerTransportTest.cpp"},"deprecated":false,"digest":{"line_hashes":["109635496399465194200365249824753989248","268241433506113120131676170924760634205","210433768695664219401397956953288459121","241238244522086551514124920129695241379","94261832321462151248039445531238162804","6513156253446097844455784851518529280","215852990144267569037920970715087428413","296481722082696841595871374931381935909","218001601192870813037414502163739957469","223587628361970460774825732875919793282","4898243644475824479626002985620819604","88171764556776383983025629606954914206"],"threshold":0.9},"id":"CVE-2025-30403-b96d41c6","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0","target":{"file":"quic/server/QuicServerTransport.cpp","function":"QuicServerTransport::registerAllTransportKnobParamHandlers"},"deprecated":false,"digest":{"function_hash":"208723450299243019982314994445398926972","length":22053},"id":"CVE-2025-30403-c273afb7"},{"target":{"file":"quic/server/test/QuicServerTransportTest.cpp","function":"TEST_F"},"deprecated":false,"digest":{"function_hash":"131352266776178433337981149495555933547","length":1174},"id":"CVE-2025-30403-cab423e0","signature_type":"Function","signature_version":"v1","source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0"},{"deprecated":false,"digest":{"line_hashes":["112413491556449806323921950655555871787","323003975541744755148479121280525306468","282787821402900262813170755968408752509","93631063314172836112038762810507550986","250827278477683185329084737067662343158"],"threshold":0.9},"id":"CVE-2025-30403-d6a6fed0","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0","target":{"file":"quic/common/BufUtil.h"}},{"id":"CVE-2025-30403-d8e3ec75","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0","target":{"file":"quic/common/test/BufUtilTest.cpp"},"deprecated":false,"digest":{"line_hashes":["25318259841628669304498105988064049258","54343792301131539265578558428474522963","135238316927150974846704469556209322648","104483566425259149333323491647665949693","302474871860117260875644444111670109765","88511704264196397464906093098424352689","284566009702899207254084659850051958906","296320280866619474700431786733373419585"],"threshold":0.9}},{"digest":{"threshold":0.9,"line_hashes":["62004651989832169906048942366993483805","285551130117691970366812518589171239233","26504857526276584604788099026189146014","53159096773085882321926762415562697007","87683309468235957172019986777384480191"]},"id":"CVE-2025-30403-e09dc165","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0","target":{"file":"quic/server/QuicServerTransport.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H"}]}