CVE-2026-91095
N/A
N/A
Summary
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| proxygen | v2024.10.28.00 < v2026.09.28.00 | affected |
Weaknesses
- Use After Free (CWE-416)
References
- https://www.facebook.com/security/advisories/cve-2026-91095
- https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.