CVEs classified under CWE-409, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-68911: Nicotine+ is a graphical client for the Soulseek peer-to-peer network. Prior to version 3.3.11, a modified remote client can send…
CVE-2026-77620: Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back…
CVE-2026-62963: Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket transport with…
CVE-2026-55195: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3…
CVE-2026-53430: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message…
CVE-2026-44697 — CVSS 8.6 (high): Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service…
CVE-2026-94637: Improper handling of highly compressed data (data amplification) vulnerability in Apache Thrift Go bindings. This issue affects Apache…
CVE-2026-94636: Improper handling of highly compressed data (data amplification), Function call with incorrectly specified arguments, Improper validation…
CVE-2026-67232: RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at…
CVE-2026-54556: Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, an unauthenticated HTTP/2 peer can cause an out-of-memory…
CVE-2026-44981: CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with…
CVE-2026-43970: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticated remote denial of…
CVE-2026-103262 — CVSS 7.5 (high): Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to…
CVE-2026-83599 — CVSS 7.5 (high): Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate…
CVE-2026-47321 — CVSS 7.5 (high): The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not…
CVE-2026-84384 — CVSS 7.5 (high): libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image…
CVE-2026-89059 — CVSS 7.5 (high): A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the…
CVE-2026-70469 — CVSS 7.5 (high): Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the…
CVE-2026-92000 — CVSS 7.5 (high): adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size…
CVE-2026-53659 — CVSS 7.5 (high): http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip…
CVE-2026-46387 — CVSS 7.5 (high): Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions…
CVE-2026-85786 — CVSS 7.5 (high): Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via…
CVE-2026-82520 — CVSS 7.5 (high): parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size…
CVE-2026-84382 — CVSS 7.5 (high): HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully…
CVE-2026-78206 — CVSS 7.5 (high): exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or…
CVE-2026-75936 — CVSS 7.5 (high): Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote…
CVE-2026-73232 — CVSS 7.5 (high): ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service…
CVE-2026-68981 — CVSS 7.5 (high): Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The…
CVE-2026-49158 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache…
CVE-2026-48586 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings…
CVE-2026-41608 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache…
CVE-2026-49855 — CVSS 7.5 (high): Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed…
CVE-2026-15709 — CVSS 7.5 (high): A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop…
CVE-2026-44160 — CVSS 7.5 (high): Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3…
CVE-2026-59939 — CVSS 7.5 (high): httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response…
CVE-2026-59803 — CVSS 7.5 (high): rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/message.go)…
CVE-2026-24264 — CVSS 7.5 (high): NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data…
CVE-2026-48044 — CVSS 7.5 (high): Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7, 1.37.3, and…
CVE-2026-54314 — CVSS 7.5 (high): n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded…
CVE-2026-48510 — CVSS 7.5 (high): MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses Lz4Block or…
CVE-2026-54278 — CVSS 7.5 (high): AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a…
CVE-2026-49755 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to…
CVE-2026-10725 — CVSS 7.5 (high): Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has no header-list size…
CVE-2026-48594 — CVSS 7.5 (high): Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via…
CVE-2026-44432 — CVSS 7.5 (high): urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the…
CVE-2026-40036 — CVSS 7.5 (high): Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause…
CVE-2026-1526 — CVSS 7.5 (high): The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate…
CVE-2026-22870 — CVSS 7.5 (high): GuardDog is a CLI tool to identify malicious PyPI packages. Prior to 2.7.1, GuardDog's safe_extract() function does not validate…
CVE-2026-22776 — CVSS 7.5 (high): cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS)…
CVE-2026-21441 — CVSS 7.5 (high): urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by…