The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Volume of CVEs assigned to CWE-409 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-49975HIGH Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP S | Jun 8, 2026 | 7.5 | 49 | NO | NO |
CVE-2026-44432HIGH urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPRes | May 13, 2026 | 7.5 | 38 | NO | NO |
CVE-2026-44697HIGH Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/bat | May 29, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-62963HIGH Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with uni_websocket.compression enabled enforced uni_ | Jul 16, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-58486HIGH HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was vulnerable to a YAML alias bomb due to unsafe processing of | Jul 13, 2026 | 8.3 | 35 | NO | NO |
CVE-2026-44160HIGH Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins su | Jul 8, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-55195HIGH py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted arc | Jul 8, 2026 | 8.7 | 35 | NO | NO |
CVE-2026-59939HIGH httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip o | Jul 8, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-44981HIGH CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with DefaultDecompressHandle globally in pkg/apiserver/ | Jul 16, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-24264HIGH NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerabilit | Jul 1, 2026 | 7.5 | 33 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.