6.5

CVE-2026-87724

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellertorprject
≫
Produkt Tor
Default Statusunaffected
Version 0.4.9.3-alpha
Version < 0.4.9.12
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.177
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
MITRE 6.5 2.2 4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
CWE-669 Incorrect Resource Transfer Between Spheres

The product does not properly transfer a resource/behavior to another sphere, or improperly imports a resource/behavior from another sphere, in a manner that provides unintended control over that resource.

https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.12/ChangeLog
https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d