Session Management Flaw in Proxygen from Facebook
CVE-2026-84895

Currently unrated

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-84895?

A session management issue in Proxygen, from versions v2026.04.06.00 to v2026.09.28.00, occurs when the QuicWtSession::closeSession function accesses its member fields post-execution of the base method, QuicWtSessionBase::closeSession. This chain of operations can inadvertently lead to the session handler releasing its last reference to the session, resulting in the session's premature destruction. Consequently, this vulnerability may expose systems to unexpected behavior during session termination, leading to potential security implications.

Affected Version(s)

proxygen v2026.04.06.00

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.