CVE-2026-77638

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
References
Link Resource
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog Permissions Required Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*

History

16 Sep 2026, 14:08

Type Values Removed Values Added
CPE cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
References () https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog - () https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog - Permissions Required, Release Notes, Vendor Advisory
First Time Torproject tor
Torproject

Information

Published : 2026-08-20 21:17

Updated : 2026-09-16 14:08


NVD link : CVE-2026-77638

Mitre link : CVE-2026-77638

CVE.ORG link : CVE-2026-77638


JSON object : View

Products Affected

torproject

  • tor
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')