Denial of Service Vulnerability in Tor Network Software
CVE-2026-87724

6.5MEDIUM

Key Information:

Vendor

Torprject

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-87724?

The Tor network software prior to version 0.4.9.12 contains a vulnerability where the CC_RESPONSE extension is interpreted without the corresponding CC_REQUEST being sent. This flaw allows remote attackers to exploit the congestion-control state, leading to a potential crash of the Tor service. As a result, affected users can experience service disruption, affecting the reliability of the network. Proper updates and patches are recommended to mitigate this issue effectively.

Affected Version(s)

Tor 0.4.9.3-alpha < 0.4.9.12

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.