Double Close Vulnerability in Tor Product by Tor Project
CVE-2026-44601

3.7LOW

Key Information:

Vendor

Torproject

Status
Vendor
CVE Published:
7 May 2026

What is CVE-2026-44601?

A memory pressure issue in Tor versions prior to 0.4.9.7 can lead to a client crash due to a double close of a circuit. This occurs when the circuit queue is under memory strain, compromising the stability of the client and potentially affecting user experience and security.

Affected Version(s)

Tor 0 < 0.4.9.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.