<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T13:07:39.376334+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-215746</id>
    <title>EUVD-2026-215746</title>
    <updated>2026-10-10T13:07:39.379561+00:00</updated>
    <content>EUVD-2026-215746</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-215746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35312</id>
    <title>fkie_cve-2024-35312</title>
    <updated>2026-10-10T13:07:39.379600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-35312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9328-gcfq-p269</id>
    <title>GHSA-9328-gcfq-p269 — Tor Arti's STUB circuits incorrectly have a length of 2</title>
    <updated>2026-10-10T13:07:39.379630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: arti, crates.io: tor-circmgr</p>
<p>In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9328-gcfq-p269"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2024-0339</id>
    <title>RUSTSEC-2024-0339 — Tor path lengths too short when "Vanguards lite" configured</title>
    <updated>2026-10-10T13:07:39.379654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: tor-circmgr</p>
<p>## Description</p>
<p>When building anonymizing circuits to or from an onion service with 
'lite' vanguards (the default) enabled, 
the circuit manager code would build the circuits with one hop too few.</p>
<p>## Impact</p>
<p>This makes users of this code more vulnerable to some kinds of traffic analysis
when they run or visit onion services.</p>
<p>## Vulnerable configurations and use cases</p>
<p>Arti configured with "vangaurds lite" is vulnerable;
this is the default.</p>
<p>Only users who make connections to Onion Services
(Tor Hidden Services) are affected.
Note, however, that when used as a browser proxy,
malicious web pages can typically make such connections.</p>
<p>## Mitigation</p>
<p>Enable the "full vanguards" feature.
This has some cost in terms of performance, reliability,
and impact on the Tor Network.</p>
<p>(Arti configured with "full vanguards" has a similar bug,
TROVE-2024-04,
so this will not deliver the full incressed security of "full vanguards";
but the security level of affected versions of Arti
configured with "full vanguards" still exceeds
the intended security level of the "vanguards lite" configuration.)</p>
<p>Alternatively,
preventing access to Tor Hidden Services will avoid the problem,
with corresponding loss of functionality.
This can be achieved in the Arti configuration file with:</p>
<p>```
[address_filter]
allow_onion_addrs = false
```</p>
<p>## Resolution</p>
<p>Rebuild `arti` (or other affected applications)
with a fixed version of `tor-circmgr`:
0.18.1 or later.</p>
<p>The fixed `tor-circmgr` is on crates.io and ava…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2024-0339"/>
  </entry>
</feed>
