CVE-2026-84894: Use After Free
Published Sep 28, 2026
·Updated
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
Affected Software
1 affected component
Facebook moxygen<004123dd24c3
Event History
Sep 28, 2026
CVE Published
via MITRE·06:40 PM
Data Sourced
via MITRE·06:40 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
Description
Frequently Asked Questions
1
What must an attacker be able to do to trigger the issue?
The attacker must act as a remote peer and open a data stream that names an unknown track alias while sending the FIN in the same write.
2
Which builds are affected and what is the available remediation?
Facebook moxygen builds before commit 004123dd24c3 are affected. Update to a build that includes commit 004123dd24c30dad6b649163575145f240dabc94.