Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
References
| Link | Resource |
|---|---|
| https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog | Release Notes Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-20 21:17
Updated : 2026-09-08 18:33
NVD link : CVE-2026-77639
Mitre link : CVE-2026-77639
CVE.ORG link : CVE-2026-77639
JSON object : View
Products Affected
torproject
- tor
CWE
CWE-420
Unprotected Alternate Channel
