This isn't actually a vulnerability yet, as SHA-1 is only known to be vulnerable to collision attacks (where you try to find two messages with the same hash) rather than pre-image attacks (where you try to find a message with a specific hash); almost no hash functions have ever been found to be vulnerable to pre-image attacks:
https://github.com/zooko/hash-function-survey/blob/master/pr... Secondly, the issue is moot because generating collisions on 80 bits takes just 2^40 work - not hard at all.
Basically what that means for Tor, is that while it'd be pretty easy for a Onion site operator to generate two keys corresponding to the same .onion address, an _attacker_ still has to do 2^80 work to attack a site by generating a key with the same Onion address. While that's not great - 2^128 work is considered "standard" in cryptographic work - 2^80 work is still hard enough that there are probably cheaper ways of attacking Onion sites (for reference, the cumulative total work done by all Bitcoin network miners in the entire history of Bitcoin is about 2^80 hashes).
As for the 1024bit pubkeys, I'm not sure what the status of that is; from what I hear Tor is actively working towards a Onion redesign that will fix these issues, and longer pubkeys may have already been fixed.