{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "0"
              },
              {
                "last_affected": "3.30.9"
              },
              {
                "introduced": "4.0.0"
              },
              {
                "last_affected": "4.8.3"
              },
              {
                "introduced": "4.9.0"
              },
              {
                "last_affected": "4.15.2"
              },
              {
                "introduced": "4.16.0"
              },
              {
                "last_affected": "4.16.3"
              },
              {
                "introduced": "4.17.0"
              },
              {
                "last_affected": "4.17.2"
              },
              {
                "introduced": "4.18.0"
              },
              {
                "last_affected": "4.18.1"
              },
              {
                "introduced": "4.20.0"
              },
              {
                "last_affected": "4.20.1"
              },
              {
                "introduced": "0"
              },
              {
                "last_affected": "4.19.0"
              }
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "4f72b676ce0907078a81b0be6283057abb2af29d"
            },
            {
              "introduced": "7d4f701b9ed004452d695fce4e1ef8f48babbf39"
            },
            {
              "last_affected": "b5d38ca640f92028e9cef407e8f5cfddda05bc9d"
            },
            {
              "introduced": "0abb3b0c92e938bb7dac2d0c1603c5866e2a035b"
            },
            {
              "last_affected": "897c11257022661a1e62fa6e6d724f62abb4798e"
            },
            {
              "introduced": "2336e00771c85df63ccb0e7c8a3004b907a3095f"
            },
            {
              "last_affected": "93b424b7a7e8af9a7306ec7a0594c2889419ed3a"
            },
            {
              "introduced": "3ba6a05af7d6372d5b8bf22ed4b30f356c99d412"
            },
            {
              "last_affected": "b02eadedd00a2922f2f26f8d541133f8d6da816e"
            },
            {
              "introduced": "429410767a2999bca955ff2c55d763dd3058dc68"
            },
            {
              "last_affected": "4bfd92104d573c0e1a11260e51ed678a6ad3a144"
            },
            {
              "introduced": "8b8ed4b4d8a9c56ae1af0f9fa38b027047049daf"
            },
            {
              "last_affected": "11774f57c04395ed69e48546287f6552005dee12"
            },
            {
              "introduced": "0"
            },
            {
              "last_affected": "e3f058f758c6ad9bda4a3c074872844aa7759cbf"
            },
            {
              "fixed": "f9680d21beaa9eb39d166e8810e29fbafa51ad15"
            }
          ],
          "repo": "https://github.com/facebook/hhvm",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "Insufficient boundary checks when processing M_SOFx markers from JPEG headers in the GD extension could allow access to out-of-bounds memory via a maliciously constructed invalid JPEG input. This issue affects HHVM versions prior to 3.30.9, all versions between 4.0.0 and 4.8.3, all versions between 4.9.0 and 4.15.2, and versions 4.16.0 to 4.16.3, 4.17.0 to 4.17.2, 4.18.0 to 4.18.1, 4.19.0, 4.20.0 to 4.20.1.",
  "id": "CVE-2019-11926",
  "modified": "2026-03-15T13:45:41.271003825Z",
  "published": "2019-09-06T19:15:11.607Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://hhvm.com/blog/2019/09/03/security-update.html"
    },
    {
      "type": "ADVISORY",
      "url": "https://www.facebook.com/security/advisories/cve-2019-11926"
    },
    {
      "type": "FIX",
      "url": "https://github.com/facebook/hhvm/commit/f9680d21beaa9eb39d166e8810e29fbafa51ad15"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}