CVE-2026-91095

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.

https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa…
https://www.facebook.com/security/advisories/cve-2026-91095