CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)

Parent: CWE-405 - Asymmetric Resource Consumption (Amplification)

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

89 vulnerabilities with CWE-409
CVE-2026-55497 MEDIUM
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
CVSS 6.5
CVE-2026-59932 HIGH
PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVSS 7.5
CVE-2026-10819 MEDIUM
Mattermost Server Denial of Service via Animated GIF Emoji Upload
CVSS 6.5
CVE-2026-49158 HIGH
Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
CVSS 7.5
CVE-2026-48586 HIGH
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
CVSS 7.5
CVE-2026-41608 HIGH
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
CVSS 7.5
CVE-2026-62963 HIGH
Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport
CVE-2026-44981 HIGH
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
CVE-2026-61449 MEDIUM
Grav before 2.0.2 Decompression Bomb via Forged ZIP Size
CVSS 6.5
CVE-2026-49855 HIGH
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
CVSS 7.5
CVE-2026-15709 HIGH
Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded decompression remote denial of service
CVSS 7.5
CVE-2026-12588 MEDIUM
Trellix HX Console - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-58486 HIGH
HedgeDoc: Denial-of-service via YAML alias expansion in note frontmatter
CVE-2026-59193 MEDIUM
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
CVSS 4.9
CVE-2026-61455 MEDIUM
Grav before 2.0.1 Decompression Bomb via ZipArchiver
CVSS 6.5
CVE-2026-44160 HIGH
Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
CVSS 7.5
CVE-2026-55195 HIGH
py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
CVE-2026-59939 HIGH
httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling
CVSS 7.5
CVE-2026-59803 HIGH
rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
CVSS 7.5
CVE-2026-55078 MEDIUM
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
CVSS 6.5
CVE-2026-24264 HIGH
Nvidia Triton Inference Server - Improper Handling of Highly Compressed Data (Data Amplification)
CVSS 7.5
CVE-2026-13523 LOW
GPAC ISOBMFF base_encoding.c data amplification
CVSS 3.3
CVE-2026-48044 HIGH
Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion
CVSS 7.5
CVE-2026-44018 MEDIUM
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
CVSS 5.5
CVE-2026-54314 HIGH
n8n: Denial of Service via ZIP decompression in webhook workflow
CVSS 7.5
Details
Vulnerabilities 89