Tor is a widely deployed anonymity and privacy-focused network whose core proxy and routing software handles encrypted traffic across a global overlay infrastructure. The vendor's vulnerability disclosures are concentrated in the singular Tor application itself and span a moderate volume over time, with recurring weakness classes centered on input validation, memory-safety issues, and information-disclosure conditions inherent to a complex, performance-sensitive networking daemon. The nature of Tor's exposure reflects the challenge of securing a high-throughput, distributed system that must handle untrusted network input while maintaining strong privacy guarantees. Defenders operating or relying on Tor infrastructure should monitor this vendor's releases for protocol-layer and implementation flaws; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tor over time
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2018-0491HIGH A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a | Mar 5, 2018 | 7.5 | 42 | NO | YES |
CVE-2026-44597CRITICAL Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | May 7, 2026 | 9.1 | 34 | NO | NO |
CVE-2010-1676HIGH Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar | Dec 22, 2010 | 10.0 | 33 | NO | NO |
CVE-2026-44603CRITICAL Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. | May 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2018-16983CRITICAL NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value. | Sep 13, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-44602HIGH Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-44601HIGH Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2020-10592HIGH Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. | Mar 23, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-8955HIGH In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memor | Feb 21, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tor.
Media articles that mention a CVE ID that affects a product developed by Tor — matched by CVE ID, not by vendor name.