CVE-2026-77587Medium· 5.9▾ SunlitTor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a cli…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
tor < 0.4.9.11Upgrade past the affected range:
tor 0.4.9.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77638High· 8.9Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
CVE-2026-77584High· 7.0Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams
CVE-2026-87724Medium· 6.5Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state
CVE-2026-77639Medium· 5.3Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely
CVE-2026-77640Low· 3.7tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1
CVE-2026-77641Medium· 6.5tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails