5.3
CVE-2026-77639
- EPSS -
- Veröffentlicht 20.08.2026 20:57:50
- Zuletzt bearbeitet 20.08.2026 21:17:11
- CVE-Watchlists
- Unerledigt
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellertorproject
≫
Produkt
Tor
Default Statusunaffected
Version
0.3.1.1-alpha
Version <
0.4.9.9
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-420 Unprotected Alternate Channel
The product protects a primary channel, but it does not use the same level of protection for an alternate channel.
https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog