CVE-2019-8955: Torproject Tor
High severity, CVSS 7.5. EPSS: 4.6% chance of exploitation in the next 30 days.
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
Affected products
- Torproject Tor: before 0.3.3.12 (fixed in 0.3.3.12); from 0.3.4.8, before 0.3.4.11 (fixed in 0.3.4.11); version 0.3.4.0 only; version 0.3.4.1 only; version 0.3.4.2 only; version 0.3.4.3 only; …
Published 2019-02-21. Last modified 2026-06-17.