CVE-2026-77642
EUVD-2026-6366520.08.2026, 22:18
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration