CVE-2026-77639
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Summary
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| torproject | Tor | 0.3.1.1-alpha < 0.4.9.9 | affected |
Weaknesses
- CWE-420: CWE-420 Unprotected Alternate Channel
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.