CVE-2026-77642
EUVD-2026-6366520.08.2026, 22:18
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.9 | CNA |
Common Weakness Enumeration