Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-24044 Details

Description

By passing invalid javascript code where await and yield were called upon non-async and non-generator getter/setter functions, Hermes would invoke generator functions and error out on invalid await/yield positions. This could result in segmentation fault as a consequence of type confusion error, with a low chance of RCE. This issue affects Hermes versions prior to v0.10.0.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')[email protected]
CWE-843Access of Resource Using Incompatible Type ('Type Confusion')[email protected]

Affected Products

ProductVersions
facebook hermes
< 0.10.0

CPE

  • cpe:2.3:a:facebook:hermes:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-24044
NVD Published Date:
Jan 15, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-24044 Details - Not Deferred