SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77587

MEDIUM · CVSS 5.9 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Tor versions prior to 0.4.9.11 are vulnerable to a use-after-free condition involving conflux objects, which could be exploited by a malicious exit node to crash the client. This vulnerability poses a medium risk, primarily affecting users relying on Tor for anonymity and security. Organizations and individuals utilizing Tor should prioritize updating to the latest version to mitigate potential disruptions and maintain system integrity.

CVE
CVE-2026-77587
Severity
MEDIUM
CVSS
5.9
EPSS
0.22%

Original NVD Description

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

Related CVEs

Other vulnerabilities affecting the same vendor(s)