CyberRota Analysis
AI-GeneratedTor versions prior to 0.4.9.12 are vulnerable to a denial-of-service attack due to improper handling of the CC_RESPONSE extension without a corresponding CC_REQUEST, potentially leading to a crash from corrupted congestion-control state. Organizations utilizing Tor for secure communications should prioritize this vulnerability to mitigate the risk of service interruptions.
CVE
CVE-2026-87724
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%
Original NVD Description
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.