VDB
CVE-2026-77587
CVE-2026-77587
PUBLISHED
CVSS 5.9 MEDIUM
Reported by mitre · Published August 20, 2026
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
Risk Scores
CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| torproject | Tor | 0.4.8.1-alpha |
| torproject | tor | 0.4.8.1-alpha, 0.4.8.1-alpha |
| torproject | Tor | 0.4.8.1-alpha, 0.4.8.1-alpha |
Timeline
- Aug 20, 2026 CVE Published
- Aug 21, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Sep 3, 2026 Security Advisory
- Sep 5, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 CVE Updated
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score