HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
{
"source": [
"CPE_RANGE",
"CPE_STRING",
"REFERENCES"
],
"cpe": [
"cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.0.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.2.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.5.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.6.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:facebook:hhvm:4.8.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.30.5"
},
{
"introduced": "4.0.0"
},
{
"last_affected": "4.0.0"
},
{
"introduced": "4.0.1"
},
{
"last_affected": "4.0.1"
},
{
"introduced": "4.0.2"
},
{
"last_affected": "4.0.2"
},
{
"introduced": "4.0.3"
},
{
"last_affected": "4.0.3"
},
{
"introduced": "4.0.4"
},
{
"last_affected": "4.0.4"
},
{
"introduced": "4.1.0"
},
{
"last_affected": "4.1.0"
},
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.0"
},
{
"introduced": "4.3.0"
},
{
"last_affected": "4.3.0"
},
{
"introduced": "4.4.0"
},
{
"last_affected": "4.4.0"
},
{
"introduced": "4.5.0"
},
{
"last_affected": "4.5.0"
},
{
"introduced": "4.6.0"
},
{
"last_affected": "4.6.0"
},
{
"introduced": "4.7.0"
},
{
"last_affected": "4.7.0"
},
{
"introduced": "4.8.0"
},
{
"last_affected": "4.8.0"
}
]
}"2026-07-08T16:08:22Z"
[
{
"target": {
"file": "hphp/runtime/server/fastcgi/fastcgi-server.cpp"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2019-3569-0e80101c",
"digest": {
"threshold": 0.9,
"line_hashes": [
"137514824064723355843894764939851756089",
"274485221879760134909049791648411818110",
"142983643094198605564629967646232518446",
"6111575993008610184694406316844627987"
]
},
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/97ef580ec2cca9a54da6f9bd9fdd9a455f6d74ed"
},
{
"target": {
"file": "hphp/runtime/server/fastcgi/fastcgi-server.cpp",
"function": "FastCGIServer::FastCGIServer"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2019-3569-71c2432d",
"digest": {
"function_hash": "244793622532617888474407837374486565622",
"length": 937.0
},
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/97ef580ec2cca9a54da6f9bd9fdd9a455f6d74ed"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3569.json"