OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-84895

HIGH · CVSS 7.3 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability in proxygen affects the QuicWtSession component, where member fields are accessed after the base closeSession method is invoked, potentially leading to dereferencing a destroyed session. This could result in undefined behavior or crashes, posing a risk to applications relying on this functionality. Organizations using affected versions of proxygen should prioritize remediation to mitigate potential stability and security issues.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84895
Severity
HIGH
CVSS
7.3
EPSS
0.19%

Original NVD Description

In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.