CVE-2026-77584: Torproject Tor
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.
Affected products
- Torproject Tor: before 0.4.9.10 (fixed in 0.4.9.10)
Published 2026-08-20. Last modified 2026-09-16.