SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77584

HIGH · CVSS 7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Tor versions prior to 0.4.9.10 are vulnerable to a use-after-free (UAF) condition due to improper handling of CONFLUX_LINK cells on circuits with attached streams. This flaw allows a malicious client to exploit the circuit management, potentially leading to memory corruption and unauthorized access to sensitive data. Organizations utilizing Tor for secure communications should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-77584
Severity
HIGH
CVSS
7
EPSS
0.18%

Original NVD Description

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.

Related CVEs

Other vulnerabilities affecting the same vendor(s)