CVE-2026-77639: Medium severity Tor Project Tor vulnerability
Published Aug 20, 2026
·Updated
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Affected Software
1 affected component
Tor Project Tor<0.4.9.9
Event History
Aug 20, 2026
CVE Published
via MITRE·08:57 PM
Data Sourced
via MITRE·08:57 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Tor versions before 0.4.9.9 are affected. The provided data does not identify any configuration-specific limitation.
2
What does an attacker need to exploit this issue?
The attack can be performed remotely with low complexity and requires neither privileges nor user interaction. The attacker must supply many concatenated gzip or zlib sub-streams, each below the per-stream detection threshold.
3
How can I determine whether I am affected, and what is the remediation?
Check the installed Tor version. Systems running a version earlier than 0.4.9.9 should be updated to 0.4.9.9 or later.