Threats Tagged 'cve-2026-77638'
View all threats tagged with 'cve-2026-77638'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-77638'
Click on any threat for detailed analysis and mitigation recommendations
0 This security update for Tor addresses multiple major bugs including race conditions in onion services, use-after-free vulnerabilities, and protocol handling issues. The fixes prevent potential crashes and improve security by correcting how introduction points and exit policies are handled. The update also restores warnings for unsafe SOCKS protocols and improves client entry guard expiration consistency. Join the discussion | GCVE Database | 08/25/2026, 20:46:16 UTC Added: 09/17/2026, 01:58:55 UTC |
CVE-2026-77584 is a high-severity vulnerability in Tor before version 0.4.9.10 involving incorrect synchronization. The flaw allows a malicious client to send a RELAY_COMMAND_BEGIN before a CONFLUX_LINK on the same circuit, causing an exit stream to become orphaned and leading to a use-after-free condition when the circuit is freed. This can impact the integrity and availability of the Tor process. Join the discussion | CVE Database V5 | 08/24/2026, 00:00:00 UTC Added: 08/20/2026, 20:52:50 UTC |
A vulnerability in Tor versions before 0.4.9.9 allows an attacker to bypass the compression bomb detection by concatenating multiple gzip or zlib sub-streams, each below the detection threshold. This flaw can lead to denial of service by causing resource exhaustion. The issue is tracked as CVE-2026-77639 and is classified under CWE-420 (Unprotected Alternate Channel). Join the discussion | CVE Database V5 | 08/20/2026, 22:00:00 UTC Added: 08/20/2026, 21:07:38 UTC |
0 A race condition vulnerability (CWE-362) exists in Tor versions from 0.3.5.3-alpha up to but not including 0.4.9.11. This flaw allows a rendezvous point to potentially man-in-the-middle and impersonate the onion service a client is attempting to reach. The vulnerability has a high severity with a CVSS score of 8.9. Join the discussion | CVE Database V5 | 08/20/2026, 20:52:29 UTC Added: 08/20/2026, 21:07:38 UTC |
Showing 1 to 4 of 4 results