CVE-2026-77638
Torproject · Published August 20, 2026
9.0
CVSS v3.1
CRITICALPatch availableGet patch
Description
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
Affected Products
- TOR < 0.4.9.11
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H