← Back to search

CVE-2026-91096

— UNSCOREDpublic exploit available

Published 2026-09-28 · Updated 2026-09-28

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destroy in releases before v2025.08.18.00) failed to unregister read callbacks for streams that were no longer open before destroying them. The transport could then invoke a read callback that had been freed.

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.