CVE-2019-11936
Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Scoring
- CVSS base score
- 0.03
- EPSS probability
- 0.64%
- CWE
- CWE-626
- Published
- 2019-12-04
- Last modified
- 2026-03-14
Affected products
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
- Facebook HHVM
Weakness type
Related vulnerabilities
- CVE-2026-76816 — Netty: MQTT Topic Name and Client ID Validation Bypass
- CVE-2026-62380 — Netty before 4.2.16.Final SOCKS Proxy Null Byte Injection
- CVE-2026-42579 — Netty: DNS Codec Input Validation Bypass in Netty (Encoder + Decoder)
- CVE-2026-42040 — Axios: Null Byte Injection via Reverse-Encoding in AxiosURLSearchParams
- CVE-2020-10773 — A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager...
- CVE-2019-17137 — This vulnerability allows network-adjacent attackers to bypass authentication on affected...