The Tor Project maintains a niche, widely scrutinized anonymity network and client software that, despite its focused product scope, occupies a critical role in privacy-sensitive infrastructure and is thus subject to careful security review. Its disclosed vulnerabilities center on memory-safety and pointer-handling weakness classes including buffer-boundary violations, NULL-pointer dereferences, and use-after-free conditions, which are characteristic of the low-level C codebase underlying the core Tor daemon and client. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tor Project over time
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2018-0491HIGH A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a | Mar 5, 2018 | 7.5 | 42 | NO | YES |
CVE-2026-44597CRITICAL Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | May 7, 2026 | 9.1 | 34 | NO | NO |
CVE-2010-1676HIGH Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar | Dec 22, 2010 | 10.0 | 33 | NO | NO |
CVE-2026-44603CRITICAL Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. | May 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2018-16983CRITICAL NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value. | Sep 13, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-44602HIGH Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-44601HIGH Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2020-10592HIGH Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. | Mar 23, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-8955HIGH In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memor | Feb 21, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tor Project.
Media articles that mention a CVE ID that affects a product developed by Tor Project — matched by CVE ID, not by vendor name.