SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-77639

MEDIUM · CVSS 5.3 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Tor versions prior to 0.4.9.9 are vulnerable to a compression bomb bypass, allowing attackers to exploit the concatenation of multiple gzip or zlib sub-streams to evade detection mechanisms. This could lead to denial-of-service conditions by overwhelming system resources. Organizations using affected Tor versions should prioritize updating to mitigate potential service disruptions.

CVE
CVE-2026-77639
Severity
MEDIUM
CVSS
5.3
EPSS
0.23%

Original NVD Description

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

Related CVEs

Other vulnerabilities affecting the same vendor(s)