CVE-2026-91096
Deferred Deferred - Pending Action

Proxygen WebTransport Use-After-Free in Session Stream Handling

Vulnerability report for CVE-2026-91096, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Facebook, Inc.

Description

In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
proxygen proxygen From 2024.10.28.00 (inc) to 2026.09.28.00 (inc)
proxygen proxygen to 2025.08.18.00 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in proxygen versions between v2024.10.28.00 and v2026.09.28.00. The function WebTransportImpl::terminateSessionStreams (or WebTransportImpl::destroy in older versions) fails to properly unregister read callbacks for closed streams before destroying them. This can lead to a use-after-free scenario where the transport invokes a callback that has already been freed.

Detection Guidance

This vulnerability is specific to proxygen versions between v2024.10.28.00 and v2026.09.28.00. Detection involves checking the installed version of proxygen. Use commands like 'grep' or 'dpkg' to inspect package versions if proxygen is installed via a package manager.

Impact Analysis

This vulnerability could cause crashes or unexpected behavior in applications using affected proxygen versions. It may lead to memory corruption, application instability, or potential remote code execution if exploited by an attacker.

Mitigation Strategies

Upgrade proxygen to a version later than v2026.09.28.00 or at least v2025.08.18.00 to address the issue with unregistered read callbacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91096. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart