CVE-2026-77584

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*

History

16 Sep 2026, 14:15

Type Values Removed Values Added
CPE cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
First Time Torproject tor
Torproject
References () https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.10/ChangeLog - () https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.10/ChangeLog - Release Notes, Vendor Advisory

Information

Published : 2026-08-20 21:17

Updated : 2026-09-16 14:15


NVD link : CVE-2026-77584

Mitre link : CVE-2026-77584

CVE.ORG link : CVE-2026-77584


JSON object : View

Products Affected

torproject

  • tor
CWE
CWE-821

Incorrect Synchronization