← Vulnerability feed

Vulnerability record · CVE-2016-1000109 · published 19 February 2020

CVE-2016-1000109: Facebook hhvm vulnerability

Facebook · Hhvm

HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. This issue affects HHVM versions prior to 3.9.6, all versions between 3.10.0 and 3.12.4 (inclusive), and all versions between 3.13.0 and 3.14.2 (inclusive).

5.3 CVSS 3.1 Medium EPSS 5.1% · top 8.0% CWE-665 · CWE-665
5.3CVSS 3.1 base score, v2 5.0
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. This issue affects HHVM versions prior to 3.9.6, all versions between 3.10.0 and 3.12.4 (inclusive), and all versions between 3.13.0 and 3.14.2 (inclusive).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-1000109 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-36937Facebook hhvm broken cryptographic algorithm vulnerabilityHHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous publish…EPSS 0.53%9.8CVE-2021-24036Facebook folly heap-based buffer overflow vulnerabilityPassing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possi…EPSS 3.3%9.8CVE-2020-1900Facebook hhvm use after free vulnerabilityWhen unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything …EPSS 1.4%9.8CVE-2021-24025Facebook hhvm heap-based buffer overflow vulnerabilityDue to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow…EPSS 1.7%9.8CVE-2020-1916Facebook hhvm heap-based buffer overflow vulnerabilityAn incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write…EPSS 1.4%9.8CVE-2020-1917Facebook hhvm heap-based buffer overflow vulnerabilityxbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its stan…EPSS 1.4%9.8CVE-2016-1000004Facebook hhvm insufficient verification of data authenticity vulnerabilityInsufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM v…EPSS 0.68%9.8CVE-2016-1000005Facebook hhvm type confusion vulnerabilitymcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2016-1000109), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.