An out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type (CVE-2026-77642). A NULL write after free when sending a CONFLUX_SWITCH cell fails, resulting in a crash (CVE-2026-77641). An infinite loop when decompressing a truncated zlib/gzip stream with done=1 (CVE-2026-77640). A compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams (CVE-2026-77639). A race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach (CVE-2026-77638). A use-after-free that a malicious exit node could use to crash a client (CVE-2026-77587). Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams (CVE-2026-77584).