DH handshake flaw causes situation first hop malicious server can lear all keay of client negotiation for the rest of the circuit.
vulners.com/securityvulns/securityvulns:doc:9530