CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
89 vulnerabilities with CWE-409
CVE-2026-54233
MEDIUM
vLLM: OOM Denial of Service via Audio Decompression Bomb
CVSS 6.5
CVE-2026-48510
HIGH
MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths
CVSS 7.5
CVE-2026-48502
HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-54278
HIGH
AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
CVSS 7.5
CVE-2026-47774
HIGH
Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification
CVSS 7.5
CVE-2026-53430
HIGH
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
CVE-2026-49975
HIGH
Apache HTTP Server: mod_http2 denial of service
CVSS 7.5
CVE-2026-49755
HIGH
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
CVE-2026-10725
HIGH
Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb
CVSS 7.5
CVE-2026-48594
HIGH
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
CVE-2026-44697
HIGH
Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
CVSS 8.6
CVE-2026-8814
MEDIUM
Exifreader < 4.39.0 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSS 5.3
CVE-2026-43970
HIGH
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
CVE-2026-44432
HIGH
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
CVSS 7.5
CVE-2026-42886
MEDIUM
Audiobookshelf: Memory amplification DoS via oversized compressed details entry in backup upload
CVSS 4.9
CVE-2026-40192
HIGH
Pillow is vulnerable to a FITS GZIP decompression bomb
CVSS 7.5
CVE-2026-27460
MEDIUM
Tandoor Recipes Affected by Denial of Service via Recipe Import
CVSS 6.5
CVE-2026-40148
MEDIUM
PraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits
CVSS 6.5
CVE-2026-40036
HIGH
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
CVSS 7.5
CVE-2026-39373
MEDIUM
JWCrypto: JWE ZIP decompression bomb
CVSS 5.3
CVE-2026-3114
MEDIUM
Zip Bomb Denial of Service via Unrestricted Archive Decompression
CVSS 6.5
CVE-2026-29785
HIGH
NATS Server panic via malicious compression on leafnode port
CVSS 7.5
CVE-2026-32044
MEDIUM
OpenClaw < 2026.3.2 - Tar Archive Safety Bypass in Skills Installation
CVSS 5.5
CVE-2026-2575
MEDIUM
Keycloak: keycloak: denial of service due to excessive samlrequest decompression
CVSS 5.3
CVE-2026-32630
MEDIUM
file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry
CVSS 5.3
Details
Vulnerabilities
89