
CVE-2026-44602 Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. https://www.cve.org/CVERecord?id=CVE-2026-44602
Post summary
The entry reports a CVE (CVE‑2026‑44602) describing a NULL pointer dereference in Tor prior to version 0.4.9.7 when a CERT cell is received out of order, but it offers no PoC, exploit code, patch, or evidence of active exploitation.


