Massive security flaws affect entire Tor network: critical patches released

Rusty Snippets

Administrator
Staff member
United-States
Key takeaways:
  • Tor issued emergency fixes for high-severity flaws affecting relays, clients, and onion services.
  • The release lists 10 tracked vulnerabilities, but full technical details are delayed to limit attacker use.
  • Some bugs could undermine anonymity by linking browsing activity across sessions or separate onion-site visits.
  • Tor Browser users may need the next release because version 15.0.23 likely lacks all fixes.
High-severity vulnerabilities are affecting Tor across the entire network: relays, clients, and onion services. The Tor Project urges upgrades ASAP, as it holds back full technical details from potential attackers.

Tor developers say that “LLM report firehose” once again delivered an avalanche of vulnerabilities.

The project released emergency “high-severity fixes” affecting “all entities” on September 23rd, 2026. The latest release of the Tor network's core software is Tor 0.4.9.13.

“The fixes affect all Tor components: relays, clients, and onion services. We strongly recommend upgrading as soon as possible,” the Tor Project said in a security announcement, relayed to the oss-security mailing list.................

 
Back
Top