PT-2026-79149 · Torproject+3 · Tor
CVE-2026-77639
·
Published
2026-08-20
·
Updated
2026-08-20
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Tor versions prior to 0.4.9.9
Description
An issue exists where a compression bomb check can be bypassed. An attacker can achieve this by concatenating multiple gzip or zlib sub-streams, ensuring each remains just below the per-stream detection threshold to evade detection entirely. A compression bomb is a malicious archive file designed to crash or freeze the system by expanding to an enormous size when decompressed.
Recommendations
Update Tor to version 0.4.9.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tor