Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Meta
Published:
Updated: 2026-09-28T18:40:55.707Z
Reserved: 2026-09-02T14:52:36.354Z
Link: CVE-2026-84894
No data.
Status : Received
Published: 2026-09-28T19:16:50.213
Modified: 2026-09-28T19:16:50.213
Link: CVE-2026-84894
No data.
OpenCVE Enrichment
Updated: 2026-09-28T21:15:07Z
No weakness.