CVE-2026-77639: CWE-420 Unprotected Alternate Channel in torproject Tor
CVE-2026-77639 is a medium severity vulnerability in Tor before version 0.4.9.9. It involves a compression bomb bypass where an attacker can concatenate multiple gzip or zlib sub-streams, each just below the detection threshold, to evade the compression bomb check. This flaw could lead to denial of service by exhausting resources.
AI Analysis
Technical Summary
Tor versions prior to 0.4.9.9 are vulnerable to a compression bomb bypass vulnerability (CWE-420) where an attacker can craft data streams composed of many gzip or zlib sub-streams, each individually below the detection threshold, thereby circumventing the compression bomb detection mechanism. This can cause resource exhaustion leading to denial of service conditions. The vulnerability is tracked as TROVE-2026-022 and assigned CVE-2026-77639. There is no vendor advisory or patch information currently available.
Potential Impact
The vulnerability allows an attacker to bypass compression bomb detection, potentially causing denial of service by consuming excessive system resources. There is no impact on confidentiality or integrity reported. The CVSS score is 5.3 (medium), reflecting a network attack vector with low complexity and no privileges or user interaction required, but limited to availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious when processing untrusted compressed data streams within affected Tor versions.
CVE-2026-77639: CWE-420 Unprotected Alternate Channel in torproject Tor
Description
CVE-2026-77639 is a medium severity vulnerability in Tor before version 0.4.9.9. It involves a compression bomb bypass where an attacker can concatenate multiple gzip or zlib sub-streams, each just below the detection threshold, to evade the compression bomb check. This flaw could lead to denial of service by exhausting resources.
CVSS v3.1
Score 5.3medium
Affected software
pkg:github/torproject/torRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Tor versions prior to 0.4.9.9 are vulnerable to a compression bomb bypass vulnerability (CWE-420) where an attacker can craft data streams composed of many gzip or zlib sub-streams, each individually below the detection threshold, thereby circumventing the compression bomb detection mechanism. This can cause resource exhaustion leading to denial of service conditions. The vulnerability is tracked as TROVE-2026-022 and assigned CVE-2026-77639. There is no vendor advisory or patch information currently available.
Potential Impact
The vulnerability allows an attacker to bypass compression bomb detection, potentially causing denial of service by consuming excessive system resources. There is no impact on confidentiality or integrity reported. The CVSS score is 5.3 (medium), reflecting a network attack vector with low complexity and no privileges or user interaction required, but limited to availability impact.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should be cautious when processing untrusted compressed data streams within affected Tor versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-20T20:57:49.855Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a876c9aacd9273b4920be02
Added to database: 08/20/2026, 21:07:38 UTC
Last enriched: 08/20/2026, 21:22:24 UTC
Last updated: 08/20/2026, 22:28:08 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.