CVE-2026-44597
Published: 07 May 2026
Summary
CVE-2026-44597 is a low-severity Incorrect Provision of Specified Functionality (CWE-684) vulnerability in Torproject Tor. Its CVSS base score is 3.7 (Low).
Operationally, ranked at the 6.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Threat & Defense Details
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Periodic checks confirm that specified security and privacy functions are actually provided and operating.
MITRE ATT&CK Enterprise TechniquesAI
Insufficient information to map techniques.NVD Description
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)