Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022. | |
| First Time appeared |
Torproject
Torproject tor |
|
| Weaknesses | CWE-420 | |
| CPEs | cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Torproject
Torproject tor |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-20T20:57:50.207Z
Reserved: 2026-08-20T20:57:49.855Z
Link: CVE-2026-77639
No data.
Status : Received
Published: 2026-08-20T21:17:11.233
Modified: 2026-08-20T21:17:11.233
Link: CVE-2026-77639
No data.
OpenCVE Enrichment
No data.
-
CWE-420
Unprotected Alternate Channel