The Tor Project has released an emergency security update to address multiple high-severity vulnerabilities affecting Tor relays, clients, and onion services across the network.
The fixes were released on September 23, with Tor 0.4.9.13 now available as the latest version of the Tor network’s core software. The Tor Project is urging users and operators to update as soon as possible.
Tor developers said an “LLM report firehose” has once again produced a large number of vulnerability reports. The project has published only limited details about the latest issues for now, with more technical information expected to be released about a week later to reduce the risk of attackers using the flaws before systems can be patched.
The release notes cover 16 categories of fixes, including 10 vulnerabilities assigned TROVE identifiers, Tor’s internal vulnerability tracking system.
Several of the issues could have serious security and privacy implications. One vulnerability appears to involve memory corruption in Tor relays, which could potentially allow attackers to crash affected systems or take control of them. The Tor Project has not confirmed whether the flaw can be used for remote code execution.
Another vulnerability could allow a malicious .onion website to connect browsing activity that should remain isolated, potentially weakening Tor’s anonymity protections. A separate stream-isolation flaw could allow a malicious onion service or HSDir relay to link activity across multiple browsing sessions.
The update also fixes a vulnerability affecting onion services that could be abused to generate excessive connection attempts, potentially taking .onion services offline. In addition, developers addressed a use-after-free vulnerability in Tor’s connection handling that could cause crashes and potentially lead to more serious exploitation.
The Tor Project said detailed technical information about the vulnerabilities, tracked through public GitLab tickets, will be published approximately one week after the security release.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Tor relay operators and other users should install the latest available updates as soon as possible. Tor Browser users should also watch for the next browser release. Tor Browser 15.0.23 was released on September 15, before these latest network-level fixes were announced, so it may not contain all of the security patches described in the new Tor release.
Tor Releases Emergency Security Update for High-Severity Vulnerabilities



