Memory Management Flaw in Proxygen by Facebook
CVE-2026-91095

Currently unrated

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-91095?

The vulnerability in Proxygen affects versions from v2024.10.28.00 to v2026.09.28.00, where the HTTPTransaction APIs can return stream handles previously freed by the stream handler. As a result, these invalid handles can be used as transport read callbacks by HQSession, leading to potential stability issues and exploitation due to the use of freed memory. Proper handling and validation of stream handles is crucial to mitigate this risk.

Affected Version(s)

proxygen v2024.10.28.00

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.