Unrated severityNVD Advisory· Published Sep 28, 2026
CVE-2026-84894
CVE-2026-84894
Description
In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <004123dd24c3
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.