Out-of-Bounds Read in Tor Network Software by The Tor Project
CVE-2026-44597

3.7LOW

Key Information:

Vendor

Torproject

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-44597?

An out-of-bounds read flaw exists in the Tor software prior to version 0.4.9.7. This vulnerability may occur when handling certain types of cells, specifically when an END, TRUNCATE, or TRUNCATED cell does not include a reason in its payload. This type of issue can potentially lead to unintended data exposure and may weaken the overall security posture of users relying on Tor for enhanced privacy.

Affected Version(s)

Tor 0 < 0.4.9.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.