The Tor Project maintains a privacy-focused anonymity network and browser ecosystem that serves millions of users globally and sits prominently in the cybersecurity landscape. Its vulnerability disclosures concentrate on the core Tor daemon and Tor Browser products and reflect the complexity of cryptographic protocol implementation, network traffic handling, and browser integration, with recurrent weakness classes including sensitive-information exposure, assertion failures, memory-safety conditions, and input-validation issues. The vendor's advisories carry particular weight because flaws in the anonymity layer or browser isolation can directly compromise user privacy, affecting both individual activists and institutional deployments that depend on Tor for security. Defenders relying on Tor for privacy should prioritize vendor updates and maintain current deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Torproject over time
Signals from CVEs in this vendor scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2018-0491HIGH A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a | Mar 5, 2018 | 7.5 | 42 | NO | YES |
CVE-2026-44597CRITICAL Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011. | May 7, 2026 | 9.1 | 34 | NO | NO |
CVE-2010-1676HIGH Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrar | Dec 22, 2010 | 10.0 | 33 | NO | NO |
CVE-2026-44603CRITICAL Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. | May 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2018-16983CRITICAL NoScript Classic before 5.1.8.7, as used in Tor Browser 7.x and other products, allows attackers to bypass script blocking via the text/html;/json Content-Type value. | Sep 13, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-44602HIGH Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-44601HIGH Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009. | May 7, 2026 | 7.5 | 28 | NO | NO |
CVE-2020-10592HIGH Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (CPU consumption), aka TROVE-2020-002. | Mar 23, 2020 | 7.5 | 26 | NO | NO |
CVE-2019-8955HIGH In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memor | Feb 21, 2019 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (108 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Torproject.
Media articles that mention a CVE ID that affects a product developed by Torproject — matched by CVE ID, not by vendor name.