Description
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
In plain language
AI Worth attentionTor versions before 0.4.9.11 can let a malicious relay impersonate an onion service during a rare connection timing issue, so small businesses using onion services should update.
A network-reachable CWE-362 race condition during Tor rendezvous establishment lets an attacker controlling the rendezvous point perform a man-in-the-middle impersonation of the target onion service.
What to do now
- Check the Tor version on every system that accesses or hosts onion services.
- If it is earlier than 0.4.9.11, plan an upgrade through your operating system or Tor supplier.
- Upgrade Tor to 0.4.9.11 or later.
- After updating, test that your onion-service connections still work as expected.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-77638 and every CVE in our database. Create a free account — no credit card required.
Create Free Account