Meta Proxygen QuicWtSession::closeSession Access closeSession (v2026.042026.09)
CVE-2026-84895 Published on September 28, 2026
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
Products Associated with CVE-2026-84895
Want to know whenever a new CVE is published for Facebook Proxygen? stack.watch will email you.
Affected Versions
Facebook proxygen:- Version v2026.04.06.00 and below v2026.09.28.00 is affected.