CVE-2026-87724: Torprject Tor
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
Affected products
- Torprject Tor: from 0.4.9.3-alpha, before 0.4.9.12 (fixed in 0.4.9.12)
Published 2026-09-09. Last modified 2026-09-09.