CVE-2026-77642: High severity The Tor Project Tor vulnerability
Published Aug 20, 2026
·Updated
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
Affected Software
1 affected component
The Tor Project Tor<0.4.9.9
Event History
Aug 20, 2026
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Tor deployments are most exposed to this issue?
Directory authorities are potentially subject to major impact. The impact is described as minor for most other Tor roles.
2
What must an attacker provide to trigger the flaw?
The issue is triggered while parsing a consensus or detached signature that contains an unexpected signature digest type. The vector is network-accessible and requires neither privileges nor user interaction, although exploitation has high attack complexity.
3
Are installations running Tor 0.4.9.9 affected?
No. The issue affects Tor versions before 0.4.9.9.