CyberRota Analysis
AI-GeneratedTor versions prior to 0.4.9.9 are vulnerable to a compression bomb bypass, allowing attackers to exploit the concatenation of multiple gzip or zlib sub-streams to evade detection mechanisms. This could lead to denial-of-service conditions by overwhelming system resources. Organizations using affected Tor versions should prioritize updating to mitigate potential service disruptions.
Original NVD Description
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
Related CVEs
Other vulnerabilities affecting the same vendor(s)