๐Ÿ” CVE Alert

CVE-2026-91096

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.

Vendor facebook
Product proxygen
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for facebook proxygen

Be the first to know when new unknown vulnerabilities affecting facebook proxygen are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Facebook / proxygen
v2024.10.28.00 < v2026.09.28.00

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
facebook.com: https://www.facebook.com/security/advisories/cve-2026-91096 github.com: https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083