Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

Project Subscriptions

Vendors Products
Torproject Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Torproject
Torproject tor
Vendors & Products Torproject
Torproject tor

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Tor Pre‑0.4.9.12 Unchecked CC_RESPONSE Causes Denial of Service

Wed, 09 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
Weaknesses CWE-669
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T18:18:39.270Z

Reserved: 2026-09-09T01:29:45.866Z

Link: CVE-2026-87724

cve-icon Vulnrichment

Updated: 2026-09-09T18:18:32.815Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T02:16:57.670

Modified: 2026-09-09T19:17:50.287

Link: CVE-2026-87724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:45:17Z

Weaknesses