Tor
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*
- >= 0.3.3.6-rc, < 0.4.9.7
A bug in Tor versions prior to 0.4.9.7 can cause a client crash under certain memory pressure conditions. This issue arises from a double closing of a circuit, which can occur when there is a backlog of circuits waiting to be processed. The vulnerability has been identified as TROVE-2026-009.
Exploitation of this vulnerability causes a client-side crash.
Users are advised to upgrade to Tor version 0.4.9.7, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.