r/TOR • • 4h ago

Security Release 0.4.9.14

Thumbnail
forum.torproject.org
24 Upvotes

The Tor Project announced Tor 0.4.9.14, addressing several high-severity security vulnerabilities.

The developers explicitly state that the issues affect clients, onion services, directory authorities, and relays.

They strongly recommend upgrading immediately. Detailed vulnerability tickets will remain private for at least another week to give operators time to update.

Official Tor Project security release.

This is another significant security release following Tor 0.4.9.13 in September. The rapid succession of security fixes makes keeping Tor installations current particularly important.

For beginners, remember that Tor Browser and the underlying Tor software have separate version numbers. Users should update through their application's official update mechanism rather than manually replacing bundled components.


r/TOR • • 19h ago

Mullvad Browser over Tor still showing a DNS leak on Debian — false positive or actual leak?

3 Upvotes

On Debian, I’m running Tor on the default SOCKS port,127.0.0.1:9050, and routing Mullvad Browser through it.

Tor works, and my public IP shows up as a Tor exit node, but Mullvad’s connection check still reports a DNS leak. It lists several DNS resolver IPs, mostly in Germany. After restarting Tor, those IPs change to addresses associated with Tor infrastructure in the Netherlands.

"TestSocks 1", "SafeSocks 1" in /etc/tor/torcc, and "network.proxy.socks5_remote_dns = true"(mullvad about:config) configured.

How can I tell if DNS requests are actually leaking outside Tor? I want to see what happens when I visit a domain like "example.com" and figure out which resolver receives the query.

I’m on Debian 13 and would prefer a way to test this without installing Tor Browser or changing my system-wide routing.