CVEs classified under CWE-409, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-62963: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with…
CVE-2026-55195: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3…
CVE-2026-53430: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message…
CVE-2026-44697 — CVSS 8.6 (high): Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service…
CVE-2026-44981: CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with…
CVE-2026-43970: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of…
CVE-2026-75936 — CVSS 7.5 (high): Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote…
CVE-2026-73232 — CVSS 7.5 (high): ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service…
CVE-2026-68981 — CVSS 7.5 (high): Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The…
CVE-2026-49158 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache…
CVE-2026-48586 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings…
CVE-2026-41608 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache…
CVE-2026-49855 — CVSS 7.5 (high): Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed…
CVE-2026-15709 — CVSS 7.5 (high): A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop…
CVE-2026-44160 — CVSS 7.5 (high): Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3…
CVE-2026-59939 — CVSS 7.5 (high): httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response…
CVE-2026-59803 — CVSS 7.5 (high): rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/message.go)…
CVE-2026-24264 — CVSS 7.5 (high): NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data…
CVE-2026-48044 — CVSS 7.5 (high): Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and…
CVE-2026-54314 — CVSS 7.5 (high): n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded…
CVE-2026-48510 — CVSS 7.5 (high): MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or…
CVE-2026-54278 — CVSS 7.5 (high): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a…
CVE-2026-49755 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to…
CVE-2026-10725 — CVSS 7.5 (high): Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size…
CVE-2026-48594 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via…
CVE-2026-44432 — CVSS 7.5 (high): urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the…
CVE-2026-40036 — CVSS 7.5 (high): Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause…
CVE-2026-1526 — CVSS 7.5 (high): The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate…
CVE-2026-22870 — CVSS 7.5 (high): GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate…
CVE-2026-22776 — CVSS 7.5 (high): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS)…
CVE-2026-21441 — CVSS 7.5 (high): urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by…
CVE-2025-69223 — CVSS 7.5 (high): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to…
CVE-2025-66909 — CVSS 7.5 (high): Turms AI-Serving module v0.10.0-SNAPSHOT and earlier contains an image decompression bomb denial of service vulnerability. The…
CVE-2025-66471 — CVSS 7.5 (high): urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles…
CVE-2025-62708 — CVSS 7.5 (high): pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF…
CVE-2025-58057 — CVSS 7.5 (high): Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers…
CVE-2024-7765 — CVSS 7.5 (high): In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of…
CVE-2024-12886 — CVSS 7.5 (high): An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API…
CVE-2025-30153 — CVSS 7.5 (high): kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if…
CVE-2024-3572 — CVSS 7.5 (high): The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted…
CVE-2024-28101 — CVSS 7.5 (high): The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2…
CVE-2026-18929: Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl…
CVE-2025-46730 — CVSS 6.8 (medium): MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that…
CVE-2026-53524 — CVSS 6.5 (medium): WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket…
CVE-2026-61690 — CVSS 6.5 (medium): Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes…