Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-77639

Опубликовано: 20 авг. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
Версия до 0.4.9.9 (исключая)

EPSS

Процентиль: 14%
0.00231
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-420

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

CVSS3: 5.3
debian
около 1 месяца назад

Tor before 0.4.9.9 was prone to acompression bomb bypass where an atta ...

CVSS3: 5.3
github
около 1 месяца назад

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

EPSS

Процентиль: 14%
0.00231
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-420