CVE detail
CVE-2026-44600
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.openwall.com/lists/oss-security/2026/05/06/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 7, 2026, 3:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/work_items/41251gitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 3:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/commit/a198185ed863677d60eec120126730628dac35bbgitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 3:16 AM - https://forum.torproject.org/c/news/tor-release-announcement/28forum.torproject.org
No excerpt available.
Release Notesforum.torproject.orgMay 7, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14169CVSS 8.1 · High
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could resu…
- CVE-2026-56355CVSS 3.7 · Low
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
- CVE-2026-49318CVSS 1.0 · Low
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the…
- CVE-2026-49317CVSS 1.0 · Low
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the…
- CVE-2026-44919CVSS 4.3 · Medium
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.
- CVE-2026-45033CVSS 8.5 · High
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a…