---
id: CVE-2026-84895
title: >-
  In proxygen from v2026.04.06.00 until v2026.09.28.00,
  QuicWtSession::closeSession accesses its member fields after calling the base
  QuicWtSessionBase::closeSession method
summary: >-
  In proxygen from v2026.04.06.00 until v2026.09.28.00,
  QuicWtSession::closeSession accesses its member fields after calling the base
  QuicWtSessionBase::closeSession method. The base method notifies the session
  handler, which may release t…
severity: none
cwe:
  - CWE-416
vendor: Facebook
product: proxygen
affected:
  - proxygen >= v2026.04.06.00 < v2026.09.28.00
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:17:19.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84895'
references:
  - url: >-
      https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083
    label: cve-assign@fb.com
  - url: 'https://www.facebook.com/security/advisories/cve-2026-84895'
    label: cve-assign@fb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T21:20:54.786Z'
---

## Overview

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
