
OtherCVSS 2.5€0
Malicious Conflux Endpoint Can Leave Stale Global OOO Queue Accounting After Teardown
aptupdate
Disclosed on HackerOne · June 16, 2026
Publicly disclosed report · by aptupdate
View original on HackerOneSummary
Tor's Conflux OOO queue accounting can remain inflated after a Conflux set is
torn down. A malicious Conflux-capable endpoint relay can send a real
CONFLUX_SWITCH gap followed by RELAY_DATA cells, causing the client to queue
out-of-order messages. When teardown happens before normal dequeue,
conflux_free_() frees those messages but does not subtract their cost from
total_ooo_q_bytes.
The victim client is unmodified in the PoC. Only the attacker-controlled exit