OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-84894

HIGH · CVSS 7.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects the MoQSession component in moxygen, where a stream read handle is improperly maintained after reading a FIN, leading to potential misuse under proxygen's WebTransport API. This flaw allows a remote peer to exploit the situation by initiating a data stream with an unknown track alias, which can result in undefined behavior or application crashes. Developers and organizations utilizing moxygen should prioritize addressing this issue to mitigate risks associated with remote exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84894
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a FIN, which invalidates the handle under proxygen's WebTransport API. A remote peer can trigger the stale use by opening a data stream that names an unknown track alias and carries the FIN in the same write.