rootpwn

critical · CVSS v3 9.8

CVE-2026-91095

The vulnerability in proxygen's HTTPTransaction APIs can expose freed memory to attackers. It affects versions from v2024.10.28.00 to v2026.

Overview

The vulnerability in proxygen's HTTPTransaction APIs can expose freed memory to attackers. It affects versions from v2024.10.28.00 to v2026.09.28.00. It allows potential memory corruption or crash.

Description

In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.

Impact

Confidentiality: potential memory disclosure. Integrity: possible memory corruption. Availability: crash or denial of service. Defenders using affected proxygen versions are at risk.

Remediation

Upgrade proxygen to v2026.10.00.00 or later. If upgrade not possible, disable WebTransport or configure HTTPTransaction to validate stream handles before use.

Risk context

Critical severity (CVSS 9.8) indicates high risk; immediate attention recommended.

Affected products

  • proxygen

Scores

Severity
critical
CVSS v2
6.4
CVSS v3
9.8
CVSS v4
—
EPSS
—

memory-safety use-after-free proxygen webtransport critical denial-of-service

← All CVEs