CVE-2026-77587
EUVD-2026-6359320.08.2026, 21:17
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.11 | CNA |
Common Weakness Enumeration