Description
Tanium addressed a compression bomb vulnerability in Threat Response.
Published: 2026-08-19
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Tanium Threat Response includes a compression bomb vulnerability that allows an attacker to craft a compressed payload which, when decompressed by the application, consumes excessive memory or CPU. The impact is resource exhaustion, leading to degraded performance or a denial of service. The weakness is classified under CWE‑409. No evidence of data disclosure or integrity compromise is provided in the current information.

Affected Systems

The affected product is Tanium Threat Response. Specific version information is not provided, so all currently installing releases should be reviewed for updates or confirmed safe by the vendor.

Risk and Exploitability

The CVSS score of 3.1 indicates low overall severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or via a domain where the Threat Response component processes user‑supplied compressed files. Based on the description, it is inferred that exploitation would require the ability to deliver a specially crafted compressed payload to the affected system.

Generated by OpenCVE AI on August 20, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Tanium Threat Response update that contains the compression bomb mitigation.
  • Reconfigure Threat Response to enforce strict limits on decompressed data size or disable decompression of untrusted files where possible.
  • Monitor system resource usage and quarantine suspicious large compressed files as an interim safeguard.

Generated by OpenCVE AI on August 20, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 20 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Tanium
Tanium threat Response
Vendors & Products Tanium
Tanium threat Response

Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Tanium addressed a compression bomb vulnerability in Threat Response.
Title Tanium addressed a compression bomb vulnerability in Threat Response.
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Tanium Threat Response
cve-icon MITRE

Status: PUBLISHED

Assigner: Tanium

Published:

Updated: 2026-08-20T15:26:33.106Z

Reserved: 2026-08-17T19:56:29.605Z

Link: CVE-2026-75476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T21:17:37.143

Modified: 2026-09-01T20:54:51.287

Link: CVE-2026-75476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:30:04Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)