CVE-2026-44603
LOWTor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Published: 5/7/2026Modified: 5/7/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (4)
https://forum.torproject.org/c/news/tor-release-announcement/28Release Noteshttps://gitlab.torproject.org/tpo/core/tor/-/commit/1703df3d439c83c2184e259fad1cfa19240f9c89Patchhttps://gitlab.torproject.org/tpo/core/tor/-/work_items/41245Broken Linkhttps://www.openwall.com/lists/oss-security/2026/05/06/8Mailing ListThird Party Advisory