CVE-2026-77640
CVE-2026-77640 is a low-severity vulnerability in Torproject Tor with a CVSS 3.x base score of 3.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1284.
Key facts
- Severity: Low (CVSS 3.x base score 3.7)
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1284
- Affected product: Torproject Tor
- Published:
- Last modified:
Description
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
Frequently asked questions
- What is CVE-2026-77640?
- tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
- How severe is CVE-2026-77640?
- CVE-2026-77640 has a CVSS 3.x base score of 3.7, rated low severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-77640 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-77640?
- CVE-2026-77640 affects Torproject Tor. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-77640?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-77640 published?
- CVE-2026-77640 was published on 2026-08-20 and last updated on 2026-09-08.
References
Affected products (1)
- cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*
More vulnerabilities in Torproject Tor
- CVE-2026-77638 — High (CVSS 8.9): Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could…
- CVE-2026-77642 — High (CVSS 7.5): tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected…
- CVE-2022-33903 — High (CVSS 7.5): Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
- CVE-2021-38385 — High (CVSS 7.5): Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and…
- CVE-2021-34550 — High (CVSS 7.5): An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows…
- CVE-2021-34549 — High (CVSS 7.5): An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of…
All CVEs affecting Torproject Tor →
Other CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities
- CVE-2026-81779 — Critical (CVSS 10.0): Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software…
- CVE-2026-49777 — Critical (CVSS 10.0): Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for…
- CVE-2024-8887 — Critical (CVSS 10.0): CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an attacker with…
- CVE-2022-20699 — Critical (CVSS 10.0): Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker…
- CVE-2021-21960 — Critical (CVSS 10.0): A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect…
- CVE-2021-21951 — Critical (CVSS 10.0): An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the…
Browse all CWE-1284 (Improper Validation of Specified Quantity in Input) vulnerabilities →