CVE-2026-77638

Summary

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

Affected Software

VendorProductVersion RangeStatus
torprojectTor0.3.5.3-alpha < 0.4.9.11affected

Weaknesses

  • CWE-362: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

References