PT-2026-102367 · Facebook · Proxygen

CVE-2026-84895

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions proxygen versions 2026.04.06.00 through 2026.09.28.00
Description A use-after-free issue exists where the QuicWtSession::closeSession() function accesses member fields after invoking the base QuicWtSessionBase::closeSession() method. Because the base method notifies the session handler, it can trigger the release of the final reference to the session, leading to its destruction before the member fields are accessed.
Recommendations Update proxygen to a version later than 2026.09.28.00.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84895

Affected Products

Proxygen