Junglewise Threat Intelligence

CVE-2026-77638: Tor race condition in onion service rendezvous

CVE-2026-77638 · Severity: high · CVSS 8.9 · Published 2026-08-20

Technologies: Torproject Tor. Vendors: Torproject.

Executive brief

Tor, a widely-used anonymity network and software, contains a race condition in its onion service (hidden service) protocol that could allow a rendezvous point to impersonate the intended destination and intercept communications. An attacker controlling a rendezvous point under specific timing conditions could perform a man-in-the-middle attack, compromising the privacy and security that users rely on Tor to provide. This affects users connecting to onion services, potentially exposing their communications to eavesdropping.

Technical details

This vulnerability is a race condition in Tor's v3 onion service rendezvous protocol. The flaw occurs when a rendezvous point (the meeting point between client and service) processes connection establishment in a way that allows insufficient validation of the service's identity under concurrent conditions. An attacker controlling or monitoring a rendezvous point can exploit this timing window to impersonate the target onion service before proper authentication is completed. The attack requires network-level access to the rendezvous point and knowledge of the target service address, but does not require authentication. The vulnerability is fixed in Tor 0.4.9.11 and later versions.

Affected products

  • Tor Project Tor before 0.4.9.11

Timeline

  • 2026-08-20: disclosed

References

Related threats