CVE-2026-91095: Facebook Proxygen
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.
Affected products
- Facebook Proxygen: from v2024.10.28.00, before v2026.09.28.00 (fixed in v2026.09.28.00)
Published 2026-09-28. Last modified 2026-09-30.