Torproject Torproject

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Torproject product.

RSS Feeds for Torproject security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Torproject products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Torproject Sorted by Most Security Vulnerabilities since 2018

Torproject Tor29 vulnerabilities

Torproject Tor Browser3 vulnerabilities

By the Year

In 2026 there have been 13 vulnerabilities in Torproject with an average score of 5.2 out of ten. Last year, in 2025 Torproject had 1 security vulnerability published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.45.




Year Vulnerabilities Average Score
2026 13 5.15
2025 1 3.70
2024 0 0.00
2023 1 6.50
2022 1 7.50
2021 6 7.13
2020 4 7.50
2019 3 0.00
2018 3 8.27

It may take a day or so for new Torproject vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Torproject Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-77642 Aug 20, 2026
Tor OOB Write in Consensus parsing before 0.4.9.9 tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
Tor
CVE-2026-77641 Aug 20, 2026
Tor <0.4.9.9 NULL Write After Free in relay_send_command_from_edge tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.
Tor
CVE-2026-77640 Aug 20, 2026
Tor <0.4.9.9: Infinite loop decompressing truncated zlib/gzip tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
Tor
CVE-2026-77639 Aug 20, 2026
Tor pre-0.4.9.9 Compression Bomb Bypass via gzip/zlib Concatenation Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Tor
CVE-2026-77638 Aug 20, 2026
Tor <0.4.9.11 Rendezvous MITM Race Condition Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
Tor
CVE-2026-77587 Aug 20, 2026
Tor Use-After-Free in conflux component before 0.4.9.11 Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
Tor
CVE-2026-77584 Aug 20, 2026
Tor <0.4.9.10 Use-after-Free via CONFLUX_LINK cell Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.
Tor
CVE-2026-44603 May 07, 2026
Tor before 0.4.9.7 OOB Read via Malformed BEGIN Cell Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
Tor
CVE-2026-44602 May 07, 2026
Tor <0.4.9.7 NULL Pointer Deref on CERT cell out-of-order Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
Tor
CVE-2026-44601 May 07, 2026
Tor 0.4.9.x DoubleClose Client Crash due to Circuit Queue Pressure Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.
Tor
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.