Tor pre-0.4.9.9 Compression Bomb Bypass via gzip/zlib Concatenation
CVE-2026-77639 Published on August 20, 2026
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Vulnerability Analysis
CVE-2026-77639 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Unprotected Alternate Channel
The software protects a primary channel, but it does not use the same level of protection for an alternate channel.
Products Associated with CVE-2026-77639
Want to know whenever a new CVE is published for Torproject Tor? stack.watch will email you.
Affected Versions
torproject Tor:- Version 0.3.1.1-alpha and below 0.4.9.9 is affected.