CVE-2026-84895EPSS p8.3%
CVE-2026-84895CVE-2026-84895
Description
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
Scoring
| CVSS | 7.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.19% probability of exploitation · percentile 8.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |