critical · CVSS v3 9.8
CVE-2026-91095
The vulnerability in proxygen's HTTPTransaction APIs can expose freed memory to attackers. It affects versions from v2024.10.28.00 to v2026.
Overview
The vulnerability in proxygen's HTTPTransaction APIs can expose freed memory to attackers. It affects versions from v2024.10.28.00 to v2026.09.28.00. It allows potential memory corruption or crash.
Description
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
Impact
Confidentiality: potential memory disclosure. Integrity: possible memory corruption. Availability: crash or denial of service. Defenders using affected proxygen versions are at risk.
Remediation
Upgrade proxygen to v2026.10.00.00 or later. If upgrade not possible, disable WebTransport or configure HTTPTransaction to validate stream handles before use.
Risk context
Critical severity (CVSS 9.8) indicates high risk; immediate attention recommended.
Affected products
- proxygen
Scores
- Severity
- critical
- CVSS v2
- 6.4
- CVSS v3
- 9.8
- CVSS v4
- —
- EPSS
- —