Session Management Flaw in Proxygen from Facebook
CVE-2026-84895
Currently unrated
What is CVE-2026-84895?
A session management issue in Proxygen, from versions v2026.04.06.00 to v2026.09.28.00, occurs when the QuicWtSession::closeSession function accesses its member fields post-execution of the base method, QuicWtSessionBase::closeSession. This chain of operations can inadvertently lead to the session handler releasing its last reference to the session, resulting in the session's premature destruction. Consequently, this vulnerability may expose systems to unexpected behavior during session termination, leading to potential security implications.
Affected Version(s)
proxygen v2026.04.06.00
