CVE-2026-84894
N/A
N/A
Summary
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Meta Platforms, Inc | moxygen | b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9 < 004123dd24c30dad6b649163575145f240dabc94 | affected |
Weaknesses
- Use After Free (CWE-416)
References
- https://www.facebook.com/security/advisories/cve-2026-84894
- https://github.com/facebookexperimental/moxygen/commit/004123dd24c30dad6b649163575145f240dabc94
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.