Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jm5p-g55h-rwhg

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

EPSS

Процентиль: 16%
0.00246
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-420

Связанные уязвимости

CVSS3: 5.3
ubuntu
20 дней назад

security update

CVSS3: 5.3
nvd
26 дней назад

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

CVSS3: 5.3
debian
26 дней назад

Tor before 0.4.9.9 was prone to acompression bomb bypass where an atta ...

EPSS

Процентиль: 16%
0.00246
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-420