MetaCVE-2026-91095
Meta proxygen: use after free
Medium5.3CVE-2026-91095 · Published Sep 28, 2026 · updated Sep 30, 2026
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| proxygen Product | >= v2024.10.28.00, < v2026.09.28.00 | v2026.09.28.00 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-416
More Meta advisories
All Meta| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Prior to v74.0.0.878.1682 of Meta Horizon OS | Critical9.1 | v74.0.0.878.1682 |
| Sep 30 | Prior to v66.0.0.733.524 of Meta Horizon OS | High8.8 | v66.0.0.733.524 |
| Sep 28 | Meta proxygen: use after free | High7.3 | v2026.09.28.00 |
| Sep 28 | Meta proxygen: use after free | High7.5 | v2026.09.28.00 |
| Sep 28 | Meta moxygen: use after free | High7.5 | 004123dd24c30dad6b649163575145f240dabc94 |
| Jul 23 | Meta proxygen: resource exhaustion | High7.5 | v2026.07.20.00 |