Vulnerability Description
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-77584?
CVE-2026-77584 is a vulnerability with a CVSS score of 7.0 (HIGH). Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the ...
How severe is CVE-2026-77584?
CVE-2026-77584 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-77584?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.