CVE-2026-77639
EUVD-2026-6364820.08.2026, 21:17
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.9 | CNA |
Common Weakness Enumeration