Description
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
Published: 2026-08-20
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Tor before 0.4.9.11 contains a use‑after‑free flaw in the handling of conflux objects when a recovery leg revives a set whose last leg has already been closed. This causes the client to crash, representing a denial‑of‑service attack. The weakness is categorized as CWE‑911, a use‑after‑free flaw.

Affected Systems

Tor users running any version older than 0.4.9.11 are vulnerable. The affected product is Tor from torproject, and all releases before 0.4.9.11 should be considered.

Risk and Exploitability

The CVSS score is 5.9, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by acting as a malicious exit node that sends a crafted circuit to the client, triggering the recovery leg logic and causing a crash. The exploit requires network proximity and the ability to control the exit node, making remote exploitation feasible from any exit node the client is willing to accept.

Generated by OpenCVE AI on August 21, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tor to version 0.4.9.11 or later to eliminate the use‑after‑free bug.
  • Configure the client to restrict or block exit nodes that could act maliciously, or use a stricter exit node selection policy.
  • Monitor Tor instances for unexpected crashes and apply service restarts or additional fallbacks as needed.

Generated by OpenCVE AI on August 21, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Tor 0.4.9.11 Leading to Crash

Thu, 20 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
First Time appeared Torproject
Torproject tor
Weaknesses CWE-911
CPEs cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
Vendors & Products Torproject
Torproject tor
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-25T19:09:06.542Z

Reserved: 2026-08-20T20:47:39.624Z

Link: CVE-2026-77587

cve-icon Vulnrichment

Updated: 2026-08-25T19:08:48.866Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-20T21:17:10.957

Modified: 2026-09-03T17:37:43.450

Link: CVE-2026-77587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:30:05Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count