← Back to browse · API

CVE-2018-6334

Severity
CRITICAL
CVSS
9.8
EPSS
0.01913
Risk score
39.87
CISA KEV
No
PoC
No
Published
2018-12-31
Modified
2025-05-06
First seen
2026-08-07
Aliases
EUVD-2018-18094, GHSA-V7MG-WG5H-PCX8
Products
Facebook:HHVM 3.21.10, Facebook:HHVM 3.22.0, Facebook:HHVM 3.24.6, Facebook:HHVM 3.25.0, Facebook:HHVM 3.25.2, Facebook:HHVM unspecified <3.21.10
Sources
euvd EUVD-2018-18094

Description

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).

References