WebTransport API Vulnerability in MoQSession by Facebook
CVE-2026-84894
Currently unrated
What is CVE-2026-84894?
In MoQSession prior to a specific commit, an issue arises where the dataStreamReadLoop continues to utilize a stream read handle after it has encountered a FIN. This situation leads to an invalid handle when operating under proxygen's WebTransport API. A remote peer can exploit this vulnerability by opening a data stream that specifies an unknown track alias while sending the FIN within the same write, potentially causing unexpected behaviors or security issues.
Affected Version(s)
moxygen b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9 < 004123dd24c30dad6b649163575145f240dabc94
