CVE-2026-77639
EUVD-2026-6364820.08.2026, 21:17
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration