CVE-2026-84894 - Moxygen Use-After-Free Vulnerability
CVE ID :CVE-2026-84894
Published : Sept. 28, 2026, 6:40 p.m. | 31 minutes ago
Description :In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 28, 2026, 6:40 p.m. | 31 minutes ago
Description :In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...