๐Ÿ” CVE Alert

CVE-2026-84894

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.

Vendor meta platforms, inc
Product moxygen
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for meta platforms, inc moxygen

Be the first to know when new unknown vulnerabilities affecting meta platforms, inc moxygen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Meta Platforms, Inc / moxygen
b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9 < 004123dd24c30dad6b649163575145f240dabc94

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
facebook.com: https://www.facebook.com/security/advisories/cve-2026-84894 github.com: https://github.com/facebookexperimental/moxygen/commit/004123dd24c30dad6b649163575145f240dabc94