SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-87724

MEDIUM · CVSS 6.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Tor versions prior to 0.4.9.12 are vulnerable to a denial-of-service attack due to improper handling of the CC_RESPONSE extension without a corresponding CC_REQUEST, potentially leading to a crash from corrupted congestion-control state. Organizations utilizing Tor for secure communications should prioritize this vulnerability to mitigate the risk of service interruptions.

CVE
CVE-2026-87724
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.