Tor pre-0.4.9.9 Compression Bomb Bypass via gzip/zlib Concatenation
CVE-2026-77639 Published on August 20, 2026

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

NVD

Vulnerability Analysis

CVE-2026-77639 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

Unprotected Alternate Channel

The software protects a primary channel, but it does not use the same level of protection for an alternate channel.


Products Associated with CVE-2026-77639

Want to know whenever a new CVE is published for Torproject Tor? stack.watch will email you.

 

Affected Versions

torproject Tor: