SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77638

HIGH · CVSS 8.9 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A race condition in Tor versions prior to 0.4.9.11 allows a malicious rendezvous point to potentially impersonate an onion service, enabling man-in-the-middle attacks. This vulnerability poses a significant risk to the confidentiality and integrity of communications for users relying on Tor for anonymity. Organizations and individuals utilizing Tor for sensitive operations should prioritize updating to the latest version to mitigate this high-severity threat.

CVE
CVE-2026-77638
Severity
HIGH
CVSS
8.9
EPSS
0.17%

Original NVD Description

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

Related CVEs

Other vulnerabilities affecting the same vendor(s)