SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-77642

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Tor versions prior to 0.4.9.9 are vulnerable to an out-of-bounds write when processing a consensus or detached signature with an unexpected signature digest type. While the impact is generally minor for most Tor roles, directory authorities could face significant risks, making it crucial for them to prioritize the update. Users operating directory authorities should ensure they upgrade to mitigate potential exploitation.

CVE
CVE-2026-77642
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

tor before 0.4.9.9 was prone to anĀ out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

Related CVEs

Other vulnerabilities affecting the same vendor(s)