CVE-2026-84895 Details
Description
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
A vulnerability exists in Facebook Proxygen versions 2026.04.06.00 prior to 2026.09.28.00, where the QuicWtSession::closeSession method improperly accesses member fields after invoking the base class's closeSession method. This oversight can lead to issues because the base method may release the last reference to the session, causing it to be destroyed prematurely.
Users can upgrade to Proxygen versions 2026.09.28.00 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083 | [email protected] | Source CodeVendor |
| https://www.facebook.com/security/advisories/cve-2026-84895 | [email protected] | AdvisoryVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Facebook proxygen | >= 2026.04.06.00, < 2026.09.28.00 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion