CVE-2018-0491: Torproject Tor

High severity, CVSS 7.5. EPSS: 14.8% chance of exploitation in the next 30 days.

A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.

Affected products

  • Torproject Tor: from 0.3.2.0, before 0.3.2.10 (fixed in 0.3.2.10)

Published 2018-03-05. Last modified 2026-06-17.