CVE-2026-44597

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

low 3.7 CVSS 3.1
Published: May 7, 2026
Modified: May 7, 2026
Vendor: Torproject
Product: Tor