PT-2026-79150 · Torproject+3 · Tor

CVE-2026-77640

·

Published

2026-08-20

·

Updated

2026-08-20

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions tor versions prior to 0.4.9.9
Description The software is prone to an infinite loop during the decompression of a truncated zlib/gzip stream when done=1. This occurs because a truncated stream does not reach Z STREAM END, leading zlib to return Z BUF ERROR when no input remains. The buf add compress() function incorrectly interprets this as a full output buffer and continuously retries the operation.
Recommendations Update to version 0.4.9.9 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77640

Affected Products

Tor