CVE-2017-0377: Torproject Tor

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.

Affected products

  • Torproject Tor: version 0.3.0.1 only; version 0.3.0.2 only; version 0.3.0.3 only; version 0.3.0.4 only; version 0.3.0.5 only; version 0.3.0.6 only; …

Published 2017-07-02. Last modified 2026-06-17.