CVE-2026-44599: Medium severity Tor Project Tor vulnerability
Published May 7, 2026
·Updated
Tor before 0.4.9.7 can attempt or accept BEGINDIR via conflux legs, aka TROVE-2026-008.
Affected Software
2 affected components
Tor Project Tor<0.4.9.7
torproject Tor<0.4.9.7
Remediation
Event History
May 7, 2026
CVE Published
via MITRE·02:11 AM
Data Sourced
via MITRE·02:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44599?
CVE-2026-44599 has been classified with a medium severity due to its potential to impact the integrity and availability of connections within the Tor network.
2
How do I fix CVE-2026-44599?
To fix CVE-2026-44599, users should upgrade their Tor software to version 0.4.9.7 or later.
3
What does CVE-2026-44599 affect?
CVE-2026-44599 affects versions of Tor prior to 0.4.9.7, specifically allowing for vulnerabilities during the handling of BEGIN_DIR requests.
4
Can CVE-2026-44599 be exploited remotely?
Yes, CVE-2026-44599 can potentially be exploited remotely, allowing attackers to affect peer connections.
5
Is CVE-2026-44599 still a concern for users of Tor?
Yes, users of Tor need to ensure they have updated to avoid being vulnerable to the issues presented by CVE-2026-44599.