CWE-409: CWE-409

21
Total CVEs
0
Critical
12
High
6.7
Avg CVSS

Yearly Trend

2026
5
2025
13
2024
3

Top Affected Vendors

1 Python 2
2 Apollographql 1
3 Framasoft 1
4 Scrapy 1
5 Gitlab 1
6 Aiohttp 1
7 Ibm 1
8 Apache 1
9 Pypdf Project 1
10 Yhirose 1

All CWE-409 CVEs (21)

CVE-2026-22776
7.5

A Denial of Service vulnerability exists in cpp-httplib where compressed HTTP request bodies are not properly limited after decompression. Attackers c...

Jan 12, 2026
CVE-2026-21441
7.5

This vulnerability in urllib3 allows a malicious server to cause excessive resource consumption on clients through decompression bombs in HTTP redirec...

Jan 7, 2026
CVE-2025-69223
7.5

AIOHTTP versions 3.13.2 and below are vulnerable to a zip bomb denial-of-service attack. An attacker can send specially crafted compressed requests th...

Jan 5, 2026
CVE-2025-66909
7.5

This vulnerability allows unauthenticated attackers to cause denial of service by uploading specially crafted image files that trigger memory exhausti...

Dec 19, 2025
CVE-2025-66471
7.5

CVE-2025-66471 is a resource exhaustion vulnerability in urllib3's streaming API that occurs when processing highly compressed HTTP responses. Attacke...

Dec 5, 2025
CVE-2025-62708
7.5

CVE-2025-62708 is a memory exhaustion vulnerability in pypdf, a popular Python PDF library. Attackers can craft malicious PDFs with LZWDecode filters ...

Oct 22, 2025
CVE-2025-58057
7.5

A denial-of-service vulnerability in Netty's BrotliDecoder and other decompression decoders allows attackers to cause out-of-memory conditions by send...

Sep 4, 2025
CVE-2024-7765
7.5

This vulnerability in h2oai/h2o-3 allows attackers to cause denial of service by uploading specially crafted large GZIP files. The server becomes unre...

Mar 20, 2025
CVE-2024-12886
7.5

This vulnerability allows attackers to crash the Ollama server by sending malicious gzip bomb HTTP responses, causing excessive memory consumption and...

Mar 20, 2025
CVE-2025-30153
7.5

This vulnerability in kin-openapi allows attackers to upload specially crafted ZIP files (like ZIP bombs) through multipart/form-data requests, causin...

Mar 19, 2025
CVE-2024-3572
7.5

This vulnerability in the Scrapy web scraping framework allows attackers to perform XML External Entity (XXE) attacks by submitting malicious XML data...

Apr 16, 2024
CVE-2024-28101
7.5

The Apollo Router versions 0.9.5 through 1.40.1 have a DoS vulnerability where highly compressed HTTP payloads cause excessive memory consumption duri...

Mar 21, 2024
CVE-2026-25962
6.5

MarkUs web application versions before 2.9.4 lack proper limits when extracting zip files, allowing attackers to cause denial of service through resou...

Mar 6, 2026
CVE-2025-63914
6.5

CVE-2025-63914 is a resource exhaustion vulnerability in Cinnamon kotaemon 0.11.0 where the ZIP file extraction function lacks proper validation. Atta...

Nov 24, 2025
CVE-2025-32949
6.5

This vulnerability allows any authenticated user to upload a Zip Bomb archive that causes disk space exhaustion when PeerTube attempts to extract it. ...

Apr 15, 2025
CVE-2024-12387
6.5

This vulnerability allows attackers to crash servers running the binary-husky/gpt_academic repository by uploading specially crafted zip bombs. When t...

Mar 20, 2025
CVE-2026-27571
5.9

This vulnerability in NATS-Server allows attackers to cause denial of service via compression bombs in WebSocket messages. It affects deployments usin...

Feb 24, 2026
CVE-2024-29370
5.3

This vulnerability in python-jose 3.3.0 allows attackers to cause Denial-of-Service (DoS) by sending malicious JWE tokens with high compression ratios...

Dec 17, 2025
CVE-2025-0986
4.5

This vulnerability in IBM PowerVM Hypervisor firmware allows a local user with specific Linux processor compatibility mode configurations to cause und...

Mar 28, 2025
CVE-2024-54016
4.3

Apache Seata (incubating) has a vulnerability where improper handling of highly compressed data can lead to data amplification attacks. This affects a...

Mar 20, 2025
CVE-2024-1947
4.3

This vulnerability allows attackers to cause a denial of service (DoS) condition in GitLab by sending specially crafted API calls. It affects all GitL...

May 23, 2024

About CWE-409 (CWE-409)

Our database tracks 21 CVEs classified as CWE-409, with 0 rated critical and 12 rated high severity. The average CVSS score for CWE-409 vulnerabilities is 6.7.

External reference: View CWE-409 on MITRE CWE →

Monitor CWE-409 Vulnerabilities

Get alerted when new CWE-409 CVEs affect your infrastructure.

Start Monitoring Free