CVE detail
CVE-2026-44601
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.openwall.com/lists/oss-security/2026/05/06/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 7, 2026, 4:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/work_items/41237gitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 4:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/commit/d4e3f6a440b58c2be661decf20c09548704907dcgitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 4:16 AM - https://forum.torproject.org/c/news/tor-release-announcement/28forum.torproject.org
No excerpt available.
Release Notesforum.torproject.orgMay 7, 2026, 4:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-42609CVSS 8.1 · High
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions)…
- CVE-2025-62784CVSS 5.3 · Medium
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement…
- CVE-2025-62783CVSS 5.0 · Medium
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElem…
- CVE-2025-62782CVSS 5.9 · Medium
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can all…
- CVE-2025-54315CVSS 7.1 · High
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
- CVE-2025-58135CVSS 5.3 · Medium
Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.