{"id":"CVE-2026-87724","details":"Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.","modified":"2026-09-11T03:30:48.916496536Z","published":"2026-09-09T01:29:46.295Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87724.json","cna_assigner":"mitre","cwe_ids":["CWE-669"]},"references":[{"type":"WEB","url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.12/ChangeLog"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87724.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87724"},{"type":"FIX","url":"https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/torproject/tor","events":[{"introduced":"1ee22f8f9a98719d32e5e4056013b68054b6448d"},{"fixed":"78923280eed3eff6a77910bba59ecc1fa2244e02"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0.4.9.3-alpha"},{"fixed":"0.4.9.12"}]}}],"versions":["tor-0.4.9.11","tor-0.4.9.10","tor-0.4.9.9","tor-0.4.9.8","tor-0.4.9.7","tor-0.4.9.6","tor-0.4.9.5","tor-0.4.9.4-rc","tor-0.4.9.3-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87724.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H"}]}