8.9
CVE-2026-77638
- EPSS -
- Veröffentlicht 20.08.2026 20:52:29
- Zuletzt bearbeitet 20.08.2026 21:17:11
- CVE-Watchlists
- Unerledigt
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellertorproject
≫
Produkt
Tor
Default Statusunaffected
Version
0.3.5.3-alpha
Version <
0.4.9.11
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 8.9 | 2.2 | 6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.11/ChangeLog