CVE-2026-91095 Details
Description
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
A use-after-free vulnerability has been identified in Facebook's Proxygen library, specifically in versions v2024.10.28.00 prior to v2026.09.28.00. The issue arises in the HTTPTransaction APIs for handling WebTransport unidirectional and bidirectional streams. These APIs could return stream handles that had already been freed by the stream handler. Consequently, the HQSession could install these handles as transport read callbacks, leading to the potential use of freed memory.
Users can upgrade to Proxygen version v2026.09.28.00 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083 | [email protected] | Source CodeVendor |
| https://www.facebook.com/security/advisories/cve-2026-91095 | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Facebook proxygen | >= 2024.10.28.00, < 2026.09.28.00 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion