Low severity3.7NVD Advisory· Published May 7, 2026· Updated May 7, 2026
CVE-2026-44597
CVE-2026-44597
Description
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- gitlab.torproject.org/tpo/core/tor/-/commit/8f98054b1982d00a14639864d03e9afd90b87481nvdPatch
- www.openwall.com/lists/oss-security/2026/05/06/8nvdMailing ListThird Party Advisory
- forum.torproject.org/c/news/tor-release-announcement/28nvdRelease Notes
News mentions
0No linked articles in our index yet.