CVE-2026-87724: Medium severity The Tor Project Tor vulnerability
Published Sep 9, 2026
·Updated
Tor before 0.4.9.12 interprets the CCRESPONSE extension even when CCREQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
Affected Software
1 affected component
The Tor Project Tor<0.4.9.12
Event History
Sep 9, 2026
CVE Published
via MITRE·01:29 AM
Data Sourced
via MITRE·01:29 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which Tor versions should be remediated?
Tor versions before 0.4.9.12 are affected. Updating to 0.4.9.12 or later addresses the affected version range.
2
Does an attacker need authentication or user interaction to exploit this issue?
No privileges or user interaction are required according to the supplied vector. Exploitation is network-reachable, though it has high attack complexity.