Threat intelligence dashboard
CVE-2026-84894Unrated

Vulnerability record

In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.

Risk score

—

CVSS unavailable

Vendor
Meta Platforms, Inc
Product
moxygen
CWE
CWE-416
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

moxygen

Meta Platforms, Inc

Version / rangeStatusType
b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9 to before 004123dd24c30dad6b649163575145f240dabc94affectedgit

Technical metrics

No CVSS metrics were provided.