CVE-2026-77639

Summary

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

Affected Software

VendorProductVersion RangeStatus
torprojectTor0.3.1.1-alpha < 0.4.9.9affected

Weaknesses

  • CWE-420: CWE-420 Unprotected Alternate Channel

References