External risk intelligence

Tor Out-of-Bounds Write in Signature Parsing

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-77642

The Tor software is network-facing by nature to facilitate anonymous communication. While Tor relays and directory authorities are publicly reachable, standard client-side Tor usage typically does not expose the consensus parsing mechanism directly to the public internet, making the exposure dependent on the specific role of the Tor instance.

Out-of-bounds Write

Torproject Tor

before 0.4.9.9

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in Tor software could allow an attacker to cause a denial of service, with potential for more significant impact on directory authorities, though most Tor roles are only minorly affected. This issue arises from how the software handles specific signature types during parsing. The primary concern is confirming if our use of Tor aligns with these affected roles and assessing any exposure.

  • Software flaw impacts how Tor handles certain signatures.
  • Directory authorities face potential major impact; others minor.
  • Confirm Tor usage and exposure within our environment.

Attack Path

How an attacker could exploit the issue

An attacker could target a Tor instance, such as a directory authority, by sending specially crafted consensus or detached signature data. This malformed data, when parsed by the vulnerable Tor software, could lead to an out-of-bounds write, potentially impacting the integrity and availability of the Tor network, particularly for directory authorities.

  • Network access is required.
  • Parsing unexpected signature data triggers the issue.
  • Risk of network integrity compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect Tor's ability to securely parse consensus or detached signature data. When parsing this data with an unexpected signature digest type, an out-of-bounds write may occur, potentially impacting the integrity and availability of the Tor service.

  • Tor's integrity and availability.
  • Parsing unexpected signature digest types.
  • Service disruption or data corruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Tor Project is responsible for the Tor software. Owners of Tor instances, especially directory authorities, should prioritize identifying and assessing the risk of affected deployments.

  • Own by Tor Project and instance operators.
  • Verify Tor instance role and reachability.
  • Update Tor to version 0.4.9.9 or later.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tor software affected by CVE-2026-77642?

Tor is core open-source software used to enable anonymous communication by routing internet traffic through a distributed network of relays. It functions as the foundation for the Tor Browser and is essential for operating relay nodes or directory authorities that maintain the network's state and consensus data.

What does out-of-bounds write mean for this vulnerability?

This vulnerability is classified as CWE-787, which occurs when a program writes data past the end of its intended memory buffer. In CVE-2026-77642, Tor's parsing logic fails to properly handle unexpected signature digest types in consensus or detached signature files, potentially overwriting adjacent memory and causing service instability.

How is this vulnerability triggered?

The issue is triggered when the software parses a specially crafted consensus or detached signature that includes an unexpected signature digest type. It does not occur during standard relay traffic processing or general anonymous browsing; the trigger requires the specific intake and parsing of malformed signature data.

Is my Tor instance at risk according to Halo Surface Signal?

Risk depends on your Tor instance's role. Halo Surface Signal notes that while Tor is inherently network-facing, standard client-side usage does not typically expose the consensus parsing mechanism to the public. Directory authorities are the most exposed, as they actively handle and parse this signature data from the network.

What should I do if I run Tor?

Identify the role of your Tor deployment to determine your exposure level. If you are operating a directory authority or any instance running a version earlier than 0.4.9.9, you should prioritize updating to version 0.4.9.9 or later to resolve the parsing flaw and protect the integrity of your service.

References