Tor Urgently Fixes Dangerous Vulnerabilities Affecting Clients, Relays, and Onion Services

27.09.2026 3 minutes Author: Newsman

Tor Project released an emergency update, Tor 0.4.9.13, fixing serious vulnerabilities that affect nearly the entire network infrastructure. Some of the flaws could weaken user anonymity and also impact the operation of onion services.

The update was released on September 23, 2026, and includes high-severity fixes affecting relays, clients, and onion services. In practice, the issues impact all major components of the Tor network. In its security advisory, the Tor Project urged users and relay operators not to delay installing the new version:

“The fixes affect all Tor components: relays, clients, and onion services. We strongly recommend upgrading as soon as possible.”

The developers have not yet disclosed the full technical details. Detailed descriptions of the vulnerabilities in the form of public GitLab tickets are expected to be released roughly a week after the update. This is intended to give users time to upgrade before potential attackers gain access to complete information about the flaws. The release notes mention 16 categories of fixes, with ten vulnerabilities receiving their own TROVE identifiers. TROVE stands for Tor Registry Of Vulnerabilities and Exposures, the project’s internal system for tracking security issues.

One of the most serious groups of flaws is related to possible memory corruption on relays. Under certain conditions, such vulnerabilities could theoretically lead to crashes or even allow an attacker to gain control of a device. Another issue allowed a malicious onion site to correlate user activity that was supposed to remain isolated. This directly affects one of Tor’s core privacy principles, keeping different sessions and websites separated in order to preserve anonymity.

A separate vulnerability in the stream isolation mechanism could allow a malicious onion service or HSDir relay to correlate user activity across different sessions. In practice, this means that actions Tor was supposed to treat as unrelated could, under certain conditions, be linked together.

Problems were also found in the operation of onion services. One flaw could create an uncontrolled stream of connection attempts, potentially allowing an attacker to generate significant load and take an onion site offline. The update also fixed a use-after-free bug in Tor’s connection-handling mechanism. These issues occur when a program continues to access a memory area after it has already been freed. In the simplest case, this can lead to connection failures or a process crash.

Memory corruption vulnerabilities can sometimes lead to remote code execution. However, the Tor Project has not stated that such a scenario is possible with the vulnerabilities fixed in this release, so there is currently no confirmed remote code execution issue.

Some of the Issues Were Found With the Help of LLMs

Tor developers also noted that this new wave of vulnerabilities once again emerged from a large volume of bug reports generated or discovered with the help of large language models. Tor referred to this as an “LLM report firehose.” The team has to review a large number of such reports, but this time some of them turned out to describe real issues that required a dedicated security update.

Tor Browser Will Also Need an Update

At the time of publication, the latest stable version of Tor Browser was 15.0.23, released on September 15, 2026. It likely does not yet include all the fixes from Tor 0.4.9.13. Tor Browser users should therefore watch for the next stable release and install it once it becomes available. For Tor relay operators, the update is already available, and the Tor Project recommends upgrading to Tor 0.4.9.13 as soon as possible.

Subscribe
Notify of
0 Коментарі
Oldest
Newest Most Voted
Found an error?
If you find an error, take a screenshot and send it to the bot.
↑