CVE-2026-75476
Awaiting Analysis Awaiting Analysis - Queue

Compression Bomb Vulnerability in Tanium Threat Response

Vulnerability report for CVE-2026-75476, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-09-01

Assigner: Tanium

Description

Tanium addressed a compression bomb vulnerability in Threat Response.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-09-01
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tanium threat_response *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a compression bomb vulnerability in Tanium Threat Response. A compression bomb is a malicious file that expands significantly when decompressed, potentially causing system resource exhaustion such as CPU, memory, or disk space overload.

Detection Guidance

Detection involves checking the installed version of Tanium Threat Response against the affected versions. Use Tanium Client commands to verify the version: 'Get-ThreatResponseVersion' or check the installed package details via 'Get-Package -Name ThreatResponse' on Windows or 'dpkg -l | grep ThreatResponse' on Linux. Ensure the version is at least v4.9.437 (2025H1), v4.12.308 (2025H2), or v4.17.277 (2026H1).

Impact Analysis

This vulnerability could lead to denial of service conditions by consuming excessive system resources. An attacker might exploit it to crash or slow down affected systems, disrupting normal operations and availability.

Compliance Impact

The provided CVE data does not specify how this vulnerability affects compliance with standards like GDPR or HIPAA. The description only mentions a compression bomb vulnerability in Tanium Threat Response without details on potential impacts to regulatory compliance.

Mitigation Strategies

Update Tanium Threat Response to the latest version provided by Tanium to address the compression bomb vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75476. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart