CVE-2026-44603: Critical severity Tor Project Tor vulnerability
Published May 7, 2026
·Updated
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Affected Software
2 affected components
Tor Project Tor<0.4.9.7
torproject Tor<0.4.9.7
Remediation
Event History
May 7, 2026
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44603?
CVE-2026-44603 has a medium severity level due to the potential out-of-bounds read vulnerability it introduces.
2
How do I fix CVE-2026-44603?
To fix CVE-2026-44603, upgrade Tor to version 0.4.9.7 or later.
3
What does CVE-2026-44603 affect?
CVE-2026-44603 affects versions of Tor prior to 0.4.9.7.
4
Can CVE-2026-44603 lead to system compromise?
CVE-2026-44603 primarily allows for an out-of-bounds read, which may lead to information disclosure but not direct system compromise.
5
Is there a workaround for CVE-2026-44603?
There are no known workarounds for CVE-2026-44603; upgrading Tor is the recommended action.