WebTransport API Vulnerability in MoQSession by Facebook
CVE-2026-84894

Currently unrated

Key Information:

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-84894?

In MoQSession prior to a specific commit, an issue arises where the dataStreamReadLoop continues to utilize a stream read handle after it has encountered a FIN. This situation leads to an invalid handle when operating under proxygen's WebTransport API. A remote peer can exploit this vulnerability by opening a data stream that specifies an unknown track alias while sending the FIN within the same write, potentially causing unexpected behaviors or security issues.

Affected Version(s)

moxygen b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9 < 004123dd24c30dad6b649163575145f240dabc94

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.