VulnSea

CWE-409

CVEs classified under CWE-409, newest first.

69 CVEsRSS

CVE-2026-74046Medium· 4.9
1mo ago

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without…

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without…

Sunlitwazuh · wazuhEPSS 0.34%via NVD
CVE-2026-19671Medium· 6.5
1mo ago

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied w…

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extracting container archives (zip/tar/rar/7z via libarchive), but those limits are not applied w…

SunlitEPSS 0.39%via NVD
CVE-2026-75047Medium· 6.5
1mo ago

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

Sunlitjetbrains · youtrackEPSS 0.88%via NVD
CVE-2026-14298Medium· 6.5
1mo ago

Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an auth…

SunlitMattermost · MattermostEPSS 0.24%via CVEORG
CVE-2026-73232High· 7.5
1mo ago

ffuf is a fast web fuzzer written in Go

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length …

Twilightffuf · github.com/ffuf/ffuf/v2EPSS 0.44%via NVD
CVE-2026-55497Medium· 6.5
1mo ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to subm…

Sunlitcloudreve · github.com/cloudreve/Cloudreve/v4EPSS 0.29%via NVD
CVE-2026-49755High
1mo ago

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

Twilightreq · reqEPSS 0.60%via GHSA
CVE-2026-59932High· 7.5
2mo ago

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion

Twilightphpoffice · phpoffice/phpspreadsheetEPSS 0.38%via GHSA
CVE-2026-56755High
2mo ago

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Gitea: Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

Twilightgitea · code.gitea.io/giteaEPSS 0.18%via GHSA
CVE-2026-55833High· 7.5
2mo ago

netty: io.netty/netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833)

A flaw was found in Netty, a network application framework. A remote attacker could exploit a vulnerability in the SPDY header decoding process. By sending a specially crafted, small compressed header block, the attacker can cause it to ex…

TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.42%via CSAF
GHSA-v626-428r-43p8High· 6.5
2mo ago

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Duplicate Advisory: Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer

Twilightgetgrav · getgrav/gravvia GHSA
GHSA-xg43-5579-qw6vMedium· 6.5
2mo ago

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files

Sunlitadawolfa · adawolfa/isdocvia GHSA
CVE-2026-15709High· 7.5PoC
2mo ago

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension

A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer si…

MidnightRed Hat · libsoup3EPSS 0.61%via NVD
CVE-2026-59200High· 7.5
2mo ago

Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)

A flaw was found in Pillow, a Python imaging library. A remote attacker could exploit a vulnerability in the PdfParser.PdfStream.decode() function when processing a crafted FlateDecode PDF stream. By providing a specially designed PDF file…

TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.39%via CSAF
CVE-2026-49855High· 7.5
2mo ago

tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)

A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…

TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.57%via CSAF
CVE-2026-59193Medium· 4.9
2mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::…

Sunlitgetgrav · gravEPSS 0.60%via NVD
GHSA-9mqm-qcwf-5qhgMedium· 5.5
2mo ago

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

CredSweeper: Recursive archive size-limit bypass in deep scanner allows crafted compressed inputs to exhaust resources

Sunlitcredsweeper · credsweepervia GHSA
CVE-2026-48594High
2mo ago

Tesla has decompression bomb on response body

Tesla has decompression bomb on response body

Twilighttesla · teslaEPSS 0.46%via GHSA
CVE-2026-59899High· 7.5
2mo ago

io.netty/netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899)

A flaw was found in the Netty netty-codec-http component. A remote attacker can send HTTP requests containing highly compressed data. The HTTP decoder in netty-codec-http fails to properly limit the decompression of this content, causing t…

TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.34%via CSAF
CVE-2026-59939High· 7.5
2mo ago

httplib2 is a comprehensive HTTP client library for Python

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allo…

Twilighthttplib2_project · httplib2EPSS 0.42%via NVD
CVE-2026-55078Medium· 6.5
2mo ago

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Sunlitcoder · github.com/coder/coder/v2EPSS 0.60%via GHSA
CVE-2026-13523Low· 3.3
2mo ago

A weakness has been identified in GPAC up to 26.02.0

A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be…

SunlitEPSS 0.16%via NVD
CVE-2026-44160High· 7.5
2mo ago

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`

Twilightfluentd · fluentdEPSS 0.62%via GHSA
CVE-2026-48502High
2mo ago

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows

TwilightMessagePack · MessagePackEPSS 0.44%via GHSA
CVE-2026-48510Medium· 7.5
2mo ago

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths

SunlitMessagePack · MessagePackEPSS 0.40%via GHSA
CVE-2026-55195Medium
3mo ago

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size

Sunlitpy7zr · py7zrEPSS 0.32%via GHSA
CVE-2026-47774High· 7.5
3mo ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remot…

Twilightenvoyproxy · envoyEPSS 0.97%via NVD
CVE-2026-54233Medium· 6.5
3mo ago

vLLM: OOM Denial of Service via Audio Decompression Bomb

vLLM: OOM Denial of Service via Audio Decompression Bomb

Sunlitvllm · vllmEPSS 0.42%via OSV
CVE-2026-54314Medium· 5.9
3mo ago

n8n: Denial of Service via ZIP decompression in webhook workflow

n8n: Denial of Service via ZIP decompression in webhook workflow

Sunlitn8n · n8nEPSS 0.55%via GHSA
CVE-2026-54278Medium
3mo ago

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup

Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CWE-409 vulnerabilities (CVEs) — page 2 · VulnSea