CVE-2026-44600: Medium severity Tor Project Tor vulnerability
Published May 7, 2026
·Updated
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
Affected Software
2 affected components
Tor Project Tor<0.4.9.7
torproject Tor<0.4.9.7
Remediation
Event History
May 7, 2026
CVE Published
via MITRE·02:20 AM
Data Sourced
via MITRE·02:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44600?
CVE-2026-44600 is considered a moderate severity vulnerability due to its impact on the accounting of the conflux out-of-order queue.
2
How do I fix CVE-2026-44600?
To fix CVE-2026-44600, update to Tor version 0.4.9.7 or later.
3
What software is affected by CVE-2026-44600?
CVE-2026-44600 affects Tor versions prior to 0.4.9.7.
4
What impact does CVE-2026-44600 have on my system?
CVE-2026-44600 may lead to improper handling of the conflux out-of-order queue, potentially affecting performance.
5
Is there a workaround for CVE-2026-44600?
There are no known workarounds for CVE-2026-44600; upgrading to the patched version is recommended.