CVE-2026-84894 Details
Description
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
A vulnerability exists in the MoQSession component of the moxygen project, specifically in versions prior to the commit 004123dd24c3. The issue arises because the dataStreamReadLoop function continues to use a stream read handle after it has processed a FIN signal, which invalidates the handle according to proxygen's WebTransport API. This creates a potential for misuse, as a remote peer can exploit this by opening a data stream with an unknown track alias and sending the FIN in the same write operation.
Users should update to the latest version of moxygen, which includes the necessary fix for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/facebookexperimental/moxygen/commit/004123dd24c30dad6b649163575145f240dabc94 | [email protected] | Source CodeVendor |
| https://www.facebook.com/security/advisories/cve-2026-84894 | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Facebook moxygen | >= b24f8e65cb83ebe5f3880cc4e3a4c8f64e1882f9, < 004123dd24c30dad6b649163575145f240dabc94 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion