CVE-2026-44600
Analyzed Analyzed - Analysis Complete
Tor 0.4.9.7 Accounting Mishandling in Conflux Queue

Publication date: 2026-05-07

Last updated on: 2026-05-07

Assigner: MITRE

Description
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-07
Last Modified
2026-05-07
Generated
2026-06-16
AI Q&A
2026-05-07
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
torproject tor to 0.4.9.7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-696 The product performs multiple related behaviors, but the behaviors are performed in the wrong order in ways that may produce resultant weaknesses.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

There is no information available in the provided context or resources regarding how CVE-2026-44600 affects compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

CVE-2026-44600 is a vulnerability in Tor versions before 0.4.9.7 where the software mishandles the accounting of the conflux out-of-order queue during the clearing of a queue. This issue is also known as TROVE-2026-010.

Impact Analysis

The vulnerability can lead to issues such as crashes or memory corruption within the Tor software. While the CVE description indicates an availability impact (CVSS score 3.7 with an impact on availability), it does not indicate direct impacts on confidentiality or integrity.

Mitigation Strategies

The Tor Project strongly recommends upgrading to Tor version 0.4.9.7 immediately to fix this vulnerability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart