Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Meta Platforms Inc
Meta Platforms Inc moxygen |
|
| Vendors & Products |
Meta Platforms Inc
Meta Platforms Inc moxygen |
Mon, 28 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write. | |
| References |
|
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2026-09-28T18:40:55.707Z
Reserved: 2026-09-02T14:52:36.354Z
Link: CVE-2026-84894
No data.
Status : Received
Published: 2026-09-28T19:16:50.213
Modified: 2026-09-28T19:16:50.213
Link: CVE-2026-84894
No data.
OpenCVE Enrichment
Updated: 2026-09-29T13:20:42Z
No weakness.