CVE-2025-30403

Source
https://cve.org/CVERecord?id=CVE-2025-30403
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30403.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-30403
Published
2025-07-11T18:26:51.212Z
Modified
2026-07-15T18:01:31.311018Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

A heap-buffer-overflow vulnerability is possible in mvfst via a specially crafted message during a QUIC session. This issue affects mvfst versions prior to v2025.07.07.00.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30403.json",
    "cna_assigner": "facebook"
}
References

Affected packages

Git / github.com/facebook/mvfst

Affected ranges

Type
GIT
Repo
https://github.com/facebook/mvfst
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "v2025.03.24.00"
        },
        {
            "fixed": "v2025.07.07.00"
        }
    ]
}

Affected versions

v2025.*
v2025.03.24.00
v2025.03.31.00
v2025.04.07.00
v2025.04.14.00
v2025.04.21.00
v2025.04.28.00
v2025.05.05.00
v2025.05.12.00
v2025.05.19.00
v2025.05.26.00
v2025.06.02.00
v2025.06.09.00
v2025.06.16.00
v2025.06.23.00
v2025.06.30.00

Database specific

vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "109635496399465194200365249824753989248",
                "268241433506113120131676170924760634205",
                "210433768695664219401397956953288459121",
                "241238244522086551514124920129695241379",
                "94261832321462151248039445531238162804",
                "6513156253446097844455784851518529280",
                "215852990144267569037920970715087428413",
                "296481722082696841595871374931381935909",
                "218001601192870813037414502163739957469",
                "223587628361970460774825732875919793282",
                "4898243644475824479626002985620819604",
                "88171764556776383983025629606954914206"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Line",
        "target": {
            "file": "quic/server/test/QuicServerTransportTest.cpp"
        },
        "id": "CVE-2025-30403-b96d41c6",
        "deprecated": false
    },
    {
        "digest": {
            "length": 22053.0,
            "function_hash": "208723450299243019982314994445398926972"
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Function",
        "target": {
            "function": "QuicServerTransport::registerAllTransportKnobParamHandlers",
            "file": "quic/server/QuicServerTransport.cpp"
        },
        "id": "CVE-2025-30403-c273afb7",
        "deprecated": false
    },
    {
        "digest": {
            "length": 1174.0,
            "function_hash": "131352266776178433337981149495555933547"
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Function",
        "target": {
            "function": "TEST_F",
            "file": "quic/server/test/QuicServerTransportTest.cpp"
        },
        "id": "CVE-2025-30403-cab423e0",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "112413491556449806323921950655555871787",
                "323003975541744755148479121280525306468",
                "282787821402900262813170755968408752509",
                "93631063314172836112038762810507550986",
                "250827278477683185329084737067662343158"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Line",
        "target": {
            "file": "quic/common/BufUtil.h"
        },
        "id": "CVE-2025-30403-d6a6fed0",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "25318259841628669304498105988064049258",
                "54343792301131539265578558428474522963",
                "135238316927150974846704469556209322648",
                "104483566425259149333323491647665949693",
                "302474871860117260875644444111670109765",
                "88511704264196397464906093098424352689",
                "284566009702899207254084659850051958906",
                "296320280866619474700431786733373419585"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Line",
        "target": {
            "file": "quic/common/test/BufUtilTest.cpp"
        },
        "id": "CVE-2025-30403-d8e3ec75",
        "deprecated": false
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "62004651989832169906048942366993483805",
                "285551130117691970366812518589171239233",
                "26504857526276584604788099026189146014",
                "53159096773085882321926762415562697007",
                "87683309468235957172019986777384480191"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/facebook/mvfst/commit/65b297332191de6e867c4a3139a233fc84c0e7e0",
        "signature_type": "Line",
        "target": {
            "file": "quic/server/QuicServerTransport.cpp"
        },
        "id": "CVE-2025-30403-e09dc165",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-07-15T18:01:31Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-30403.json"