---
id: CVE-2026-91095
title: >-
  In proxygen from v2024.10.28.00 until v2026.09.28.00, the
  HTTPTransaction::onWebTransportUniStream and
  HTTPTransaction::onWebTransportBidiStream APIs could return stream handles
  that the stream handler had already freed
summary: >-
  In proxygen from v2024.10.28.00 until v2026.09.28.00, the
  HTTPTransaction::onWebTransportUniStream and
  HTTPTransaction::onWebTransportBidiStream APIs could return stream handles
  that the stream handler had already freed. HQSession then i…
severity: none
cwe:
  - CWE-416
vendor: Facebook
product: proxygen
affected:
  - proxygen >= v2024.10.28.00 < v2026.09.28.00
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:17:19.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91095'
references:
  - url: >-
      https://github.com/facebook/proxygen/commit/479eb5574195764e80e6cedebef669f6baa85083
    label: cve-assign@fb.com
  - url: 'https://www.facebook.com/security/advisories/cve-2026-91095'
    label: cve-assign@fb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T21:20:54.787Z'
---

## Overview

In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of freed memory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
