CVE-2026-77642: High severity The Tor Project Tor vulnerability

Published Aug 20, 2026
·
Updated

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.

Affected Software

1 affected component
The Tor Project Tor<0.4.9.9

Event History

Aug 20, 2026
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which Tor deployments are most exposed to this issue?

Directory authorities are potentially subject to major impact. The impact is described as minor for most other Tor roles.

2

What must an attacker provide to trigger the flaw?

The issue is triggered while parsing a consensus or detached signature that contains an unexpected signature digest type. The vector is network-accessible and requires neither privileges nor user interaction, although exploitation has high attack complexity.

3

Are installations running Tor 0.4.9.9 affected?

No. The issue affects Tor versions before 0.4.9.9.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203