CVE detail
CVE-2026-44603
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://www.openwall.com/lists/oss-security/2026/05/06/8www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 7, 2026, 4:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/work_items/41245gitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 4:16 AM - https://gitlab.torproject.org/tpo/core/tor/-/commit/1703df3d439c83c2184e259fad1cfa19240f9c89gitlab.torproject.org
No excerpt available.
Patchgitlab.torproject.orgMay 7, 2026, 4:16 AM - https://forum.torproject.org/c/news/tor-release-announcement/28forum.torproject.org
No excerpt available.
Release Notesforum.torproject.orgMay 7, 2026, 4:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-11771CVSS 7.0 · High
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via…
- CVE-2026-14899CVSS 7.5 · High
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read fr…
- CVE-2026-44687CVSS 3.7 · Low
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the in…
- CVE-2026-50497CVSS 6.5 · Medium
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58380CVSS 7.3 · High
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of…
- CVE-2026-12413CVSS 7.5 · High
An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_in…