Denial of Service Vulnerability in Tor Network Software
CVE-2026-87724
6.5MEDIUM
What is CVE-2026-87724?
The Tor network software prior to version 0.4.9.12 contains a vulnerability where the CC_RESPONSE extension is interpreted without the corresponding CC_REQUEST being sent. This flaw allows remote attackers to exploit the congestion-control state, leading to a potential crash of the Tor service. As a result, affected users can experience service disruption, affecting the reliability of the network. Proper updates and patches are recommended to mitigate this issue effectively.
Affected Version(s)
Tor 0.4.9.3-alpha < 0.4.9.12
