Session Management Flaw in Proxygen Affecting Facebook's WebTransport Implementation
CVE-2026-91096

Currently unrated

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-91096?

A flaw in the Proxygen's WebTransport implementation allows for the failure to unregister read callbacks for streams that are no longer active before they are destroyed. This oversight can lead to scenarios where freed read callbacks might still be invoked by the transport mechanism, potentially resulting in unexpected behavior or crashes.

Affected Version(s)

proxygen v2024.10.28.00

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.