CVE-2025-30403
Published Jul 11, 2025
·Updated
A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.
Affected Software
1 affected component
Facebook mvfst<v2025.07.07.00
Event History
Jul 11, 2025
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-30403?
CVE-2025-30403 is classified as a high severity vulnerability due to its potential to cause a heap-buffer-overflow.
2
How do I fix CVE-2025-30403?
To fix CVE-2025-30403, update your mvfst to version v2025.07.07.00 or later.
3
What components are affected by CVE-2025-30403?
CVE-2025-30403 affects mvfst versions earlier than v2025.07.07.00.
4
What type of vulnerability is CVE-2025-30403?
CVE-2025-30403 is a heap-buffer-overflow vulnerability that can be exploited during a QUIC session.
5
What can happen if CVE-2025-30403 is exploited?
Exploitation of CVE-2025-30403 may lead to application crashes or arbitrary code execution.