tor-0.4.9.14 released
Tor 0.4.9.14 fixes high-severity bugs affecting relays, clients, onion services, and authorities.
The Tor Project published tor-0.4.9.14 on 7 October 2026 as an urgent security release. The changelog describes major bugfixes for high-severity issues affecting relays, clients, onion services, and directory authorities. One fix accepts a CONFLUX_LINK cell only on a plain OR circuit. Operators are strongly advised to upgrade immediately; the notice lists no CVE identifiers and does not report in-the-wild exploitation.
- Tor 0.4.9.14 is an urgent security release for high-severity bugs.
- Fixes affect relays, clients, onion services, and directory authorities.
- CONFLUX_LINK cells are accepted only on plain OR circuits.
- No CVE IDs or confirmed exploitation are stated in the notice.
Posted by Sam James on Oct 07 """ @@ -1,3 +1,136 @@ +Changes in version 0.4.9.14 - 2026-10-07 + Another week, another security release. This again contains major bugfixes + related to high severity issues. The fixes affect all Tor components: relay, + client, onion service and authority. We strongly recommend upgrading as soon + as possible. + + o Major bugfixes (conflux, relay, security): + - Only accept a CONFLUX_LINK cell on a plain OR circuit, and...
This source does not provide full text. Read it at seclists.org.