-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| arti | rust | = 1.2.2 | 1.2.3 |
| tor-circmgr | rust | = 0.18.0 | 0.18.1 |
The vulnerability stems from incorrect circuit path length calculation in HS circuit handling. The primary function HsCircPool::get_or_launch_required was modified in the security patches to add missing circuit extension logic for STUB circuits. The CircBuilder::build function is implicated through its role in path construction and length validation. These functions would appear in stack traces when creating onion service circuits with vulnerable path length calculations.
KEV Misses 88% of Exploited CVEs- Get the report