External risk intelligence

Tor Rendezvous Point Race Condition Man-in-the-Middle Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-77638

Tor is a client-side anonymity network application that runs on user machines. It is not designed to be a public-facing internet service, API, or gateway. While it connects to the Tor network, it does not typically expose a reachable attack surface to the public internet in the manner of a server or web application, making widespread internet-facing exposure unlikely.

Torproject Tor

before 0.4.9.11

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a critical vulnerability in Tor, a technology designed for anonymous internet communication. The issue involves a specific type of software flaw that, under precise conditions, could allow an attacker to impersonate an onion service, potentially leading to a man-in-the-middle attack and compromising the confidentiality and integrity of communications. The primary concern is to determine if your organization utilizes or is exposed to this specific version of Tor and its associated risks.

  • A flaw could allow impersonation of onion services.
  • Understand if Tor is used to confirm exposure.
  • Assess if affected technology is in use.

Attack Path

How an attacker could exploit the issue

An attacker could potentially intercept traffic destined for a Tor onion service by exploiting a race condition. This requires the attacker to be in a specific network position to impersonate the onion service to a connecting client, leading to a man-in-the-middle attack.

  • Network access and precise timing are required.
  • A rendezvous point can be impersonated.
  • Confidentiality, integrity, and availability risks.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to impersonate an onion service, potentially leading to sensitive information being disclosed or modified when users attempt to connect to that service. This relies on a specific timing vulnerability within the Tor network's rendezvous point.

  • Onion service impersonation.
  • Race condition at rendezvous point.
  • Disclosure or modification of data.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Tor could allow an attacker to impersonate an onion service, potentially leading to man-in-the-middle attacks. Identifying the scope of affected deployments and understanding their criticality is the first step for the relevant teams to plan remediation.

  • Onion service owners should confirm exposure.
  • Verify client reachability and business impact.
  • Plan risk-based remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Tor and how does it function?

Tor is an anonymity network application that routes internet traffic through volunteer-operated relays. It protects user identity and privacy by obscuring a user's location and usage. The software package includes the client-side tools and service components that enable users to access the network and host onion services.

What does CVE-2026-77638 mean for Tor security?

This vulnerability is classified as a race condition, identified as CWE-362. In programming, this occurs when the system's security depends on the timing or sequence of uncontrollable events. In this specific case, the flaw could allow a rendezvous point to incorrectly impersonate an onion service, enabling an attacker to perform a man-in-the-middle attack.

How does an attacker trigger this vulnerability?

An attacker must achieve a specific network position to act as a rendezvous point between a client and an onion service. Success requires precise timing to win the race condition. General browsing or standard Tor usage does not trigger this; the attacker must be actively positioned to intercept and manipulate the handshake process.

Is my deployment at risk from this vulnerability?

According to Halo Surface Signal, Tor is typically a client-side application and not designed as a public-facing service or gateway. Because it does not inherently expose a wide, internet-facing attack surface like a standard web server, the likelihood of widespread external exposure is very low.

How should I respond to this Tor security issue?

First, identify if you are running a version of Tor earlier than 0.4.9.11. If you operate infrastructure that hosts onion services, verify your software version and prioritize updates. If you only use Tor as a client, ensure your client software is regularly updated to benefit from the latest security improvements.

References