rootpwn

critical · CVSS v3 9.8

CVE-2026-84895

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli…

Description

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
—
EPSS
—

← All CVEs