CVE-2026-44601
Analyzed
Analyzed - Analysis Complete
Tor 0.4.9.7 Circuit Queue Memory Double Close Crash
Publication date: 2026-05-07
Last updated on: 2026-05-08
Assigner: MITRE
Description
Description
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| torproject | tor | to 0.4.9.7 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-837 | The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction. |