Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach. | |
| First Time appeared |
Torproject
Torproject tor |
|
| Weaknesses | CWE-362 | |
| CPEs | cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Torproject
Torproject tor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-20T20:52:29.708Z
Reserved: 2026-08-20T20:52:29.384Z
Link: CVE-2026-77638
No data.
Status : Received
Published: 2026-08-20T21:17:11.097
Modified: 2026-08-20T21:17:11.097
Link: CVE-2026-77638
No data.
OpenCVE Enrichment
No data.
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')