CVE-2026-77640

CVE-2026-77640 is a low-severity vulnerability in Torproject Tor with a CVSS 3.x base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1284.

Key facts

Description

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.

Frequently asked questions

What is CVE-2026-77640?
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
How severe is CVE-2026-77640?
CVE-2026-77640 has a CVSS 3.x base score of 3.7, rated low severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
Is CVE-2026-77640 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-77640?
CVE-2026-77640 affects Torproject Tor. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-77640?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-77640 published?
CVE-2026-77640 was published on 2026-08-20 and last updated on 2026-09-08.

References

Affected products (1)

More vulnerabilities in Torproject Tor

All CVEs affecting Torproject Tor →

Other CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities

Browse all CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities →