Torproject
6 known vulnerabilities
Top Products
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-202
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,
Frequently Asked Questions
How many CVEs affect Torproject?
Torproject has 6 CVE records in our database, including 0 critical and 0 high severity vulnerabilities.
What are the most severe Torproject vulnerabilities?
Torproject has 0 critical severity (CVSS 9.0+) and 0 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Torproject vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Torproject products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Torproject Vulnerabilities
CyberStrike scans your infrastructure for Torproject vulnerabilities and provides real-time remediation guidance.
Get Started