Multiple Critical Vulnerabilities Discovered in Tor Network

Multiple Critical Vulnerabilities Discovered in Tor Network

First seen 10 Sep 2026, 18:47 UTC LinuxsecurityRedpacketsecurity 57.8

Article Content

Browse articles
ThreatCluster

Recent advisories have disclosed several critical vulnerabilities affecting the Tor network, including an out-of-bounds read and multiple memory safety issues. The vulnerabilities, identified as CVE-2026-77642, CVE-2026-77641, CVE-2026-77640, CVE-2026-77639, CVE-2026-77638, and CVE-2026-77587, were published on August 20, 2026. The most notable issue involves a heap out-of-bounds read triggered by a malformed `RELAY_END` cell, which could lead to denial of service. Attackers could exploit these vulnerabilities through specially crafted messages, potentially affecting users of Tor before version 0.4.9.10. The Tor Project has confirmed the vulnerabilities and released patches for affected versions. Security professionals are advised to update their systems immediately to mitigate risks. The vulnerabilities were reported through the Internet Bug Bounty program, highlighting the importance of community engagement in security.

Key Points: • Multiple critical vulnerabilities in Tor affect versions before 0.4.9.10. • CVE-2026-77642 and others involve memory safety issues and out-of-bounds reads. • Immediate patching is required to mitigate potential exploitation risks.

Ask AI about this cluster

Timeline

2026-08-20
CVE vulnerabilities published
Six CVEs related to Tor vulnerabilities were published, including critical memory issues.
Linuxsecurity
2026-08-20
CVE-2026-77640 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77587 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77639 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77638 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77641 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77584 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-77642 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-10
HackerOne report submitted
A report detailing a heap out-of-bounds read in Tor's Conflux traffic-handling code was submitted.
Redpacketsecurity
2026-09-10
Tor releases patches
Tor Project confirmed the vulnerabilities and released patches for versions 0.4.8 and 0.4.9.
Redpacketsecurity