CVE-2026-77642: Torproject Tor
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
Affected products
- Torproject Tor: before 0.4.9.9 (fixed in 0.4.9.9)
Published 2026-08-20. Last modified 2026-09-08.