Torproject
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Torproject product.
RSS Feeds for Torproject security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Torproject products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Torproject Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 13 vulnerabilities in Torproject with an average score of 5.2 out of ten. Last year, in 2025 Torproject had 1 security vulnerability published. That is, 12 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.45.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 13 | 5.15 |
| 2025 | 1 | 3.70 |
| 2024 | 0 | 0.00 |
| 2023 | 1 | 6.50 |
| 2022 | 1 | 7.50 |
| 2021 | 6 | 7.13 |
| 2020 | 4 | 7.50 |
| 2019 | 3 | 0.00 |
| 2018 | 3 | 8.27 |
It may take a day or so for new Torproject vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Torproject Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-77642 | Aug 20, 2026 |
Tor OOB Write in Consensus parsing before 0.4.9.9tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019. |
|
| CVE-2026-77641 | Aug 20, 2026 |
Tor <0.4.9.9 NULL Write After Free in relay_send_command_from_edgetor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017. |
|
| CVE-2026-77640 | Aug 20, 2026 |
Tor <0.4.9.9: Infinite loop decompressing truncated zlib/gziptor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021. |
|
| CVE-2026-77639 | Aug 20, 2026 |
Tor pre-0.4.9.9 Compression Bomb Bypass via gzip/zlib ConcatenationTor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022. |
|
| CVE-2026-77638 | Aug 20, 2026 |
Tor <0.4.9.11 Rendezvous MITM Race ConditionTor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach. |
|
| CVE-2026-77587 | Aug 20, 2026 |
Tor Use-After-Free in conflux component before 0.4.9.11Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026. |
|
| CVE-2026-77584 | Aug 20, 2026 |
Tor <0.4.9.10 Use-after-Free via CONFLUX_LINK cellTor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025. |
|
| CVE-2026-44603 | May 07, 2026 |
Tor before 0.4.9.7 OOB Read via Malformed BEGIN CellTor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. |
|
| CVE-2026-44602 | May 07, 2026 |
Tor <0.4.9.7 NULL Pointer Deref on CERT cell out-of-orderTor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. |
|
| CVE-2026-44601 | May 07, 2026 |
Tor 0.4.9.x DoubleClose Client Crash due to Circuit Queue PressureTor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. |
|