CVE-2026-87724

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 02:16

Updated : 2026-09-09 19:17


NVD link : CVE-2026-87724

Mitre link : CVE-2026-87724

CVE.ORG link : CVE-2026-87724


JSON object : View

Products Affected

No product.

CWE
CWE-669

Incorrect Resource Transfer Between Spheres