UNKNOWN NVD
CVE-2026-84894
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under p
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
References
- https://github.com/facebookexperimental/moxygen/commit/004123dd24c30dad6b649163575145f240d
- https://www.facebook.com/security/advisories/cve-2026-84894
This unknown severity vulnerability was published on 2026-09-28 via NVD.
vulnfeed aggregates 13624 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.