← Vulnerability feed

Vulnerability record · CVE-2026-77638 · published 20 August 2026

CVE-2026-77638: Torproject tor race condition vulnerability

Torproject · Tor

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

9.0 CVSS 3.1 Critical EPSS 0.30% · top 79.8% CWE-362 · Race condition
9.0CVSS 3.1 base score
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
16 Sep 2026Last modified by NVD

Description

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog Permissions RequiredRelease NotesVendor Advisory

Track CVE-2026-77638 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2016-9079Firefox and Tor Browser SVG Animation use-after-freeA use-after-free flaw in SVG Animation affects Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1. Mozilla reports an ex…KEVEPSS 87%analysed9.3CVE-2026-77642Torproject tor out-of-bounds write vulnerabilitytor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact i…EPSS 0.35%9.1CVE-2026-44603Torproject tor vulnerabilityTor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.EPSS 0.63%9.1CVE-2026-44597Torproject tor vulnerabilityTor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.EPSS 0.63%8.2CVE-2026-77641Torproject tor unchecked return value vulnerabilitytor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() …EPSS 0.35%8.2CVE-2026-77584Torproject tor vulnerabilityTor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a …EPSS 0.25%7.5CVE-2026-77587Torproject tor use after free vulnerabilityTor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last…EPSS 0.40%7.5CVE-2026-44601Torproject tor vulnerabilityTor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-0…EPSS 0.60%

Source: NIST National Vulnerability Database (record CVE-2026-77638), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.