High severity7.5NVD Advisory· Published Mar 19, 2021· Updated Jun 17, 2026
CVE-2021-28089
CVE-2021-28089
Description
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*range: <0.3.5.14
- cpe:2.3:a:torproject:tor:0.4.4.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:torproject:tor:0.4.4.1:alpha:*:*:*:*:*:*
- cpe:2.3:a:torproject:tor:0.4.4.2:alpha:*:*:*:*:*:*
- cpe:2.3:a:torproject:tor:0.4.4.3:alpha:*:*:*:*:*:*
- (no CPE)range: <0.4.5.7
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- The Tor Project/Tordescription
- osv-coords3 versionspkg:rpm/opensuse/tor&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/tor&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tor&distro=SUSE%20Package%20Hub%2015%20SP2
< 0.4.5.7-lp152.2.9.1+ 2 more
- (no CPE)range: < 0.4.5.7-lp152.2.9.1
- (no CPE)range: < 0.4.6.7-2.2
- (no CPE)range: < 0.4.5.7-bp152.2.9.1
Patches
Vulnerability mechanics
References
4- blog.torproject.org/node/2009nvdRelease NotesVendor Advisory
- gitlab.torproject.org/tpo/core/tor/-/issues/40304nvdVendor Advisory
- security.gentoo.org/glsa/202107-25nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPDXB2GZHG3VNOTWSXQ3QZVHNV76WCU5/nvd
News mentions
0No linked articles in our index yet.