CVE-2026-87724
Dashboard / Vulnerabilities / CVE-2026-87724
CVE-2026-87724
Published: 9 Sept 2026Last Modified: 11 Sept 2026
Summary:
Details: Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
References: https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.12/ChangeLog, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87724.json, https://nvd.nist.gov/vuln/detail/CVE-2026-87724, https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 1ee22f8f9a98719d32e5e4056013b68054b6448d
Affected versions
tor-0.4.9.11
tor-0.4.9.10
tor-0.4.9.9
tor-0.4.9.8
tor-0.4.9.7
tor-0.4.9.6
tor-0.4.9.5
tor-0.4.9.4-rc
tor-0.4.9.3-alpha
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
