CVE-2026-77642

tor before 0.4.9.9 was prone to anĀ out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
References
Link Resource
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog Permissions Required Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-20 22:18

Updated : 2026-09-08 18:11


NVD link : CVE-2026-77642

Mitre link : CVE-2026-77642

CVE.ORG link : CVE-2026-77642


JSON object : View

Products Affected

torproject

  • tor
CWE
CWE-787

Out-of-bounds Write