CWE-409 · 127 kayıt
Improper Handling of Highly Compressed Data (Data Amplification)
Bu sınıftaki CVE’ler
127 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2026-21441İstismar yok | urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)python · urllib3 · CWE-409 | Yüksek8,9 | — | %3,0 | 7 Oca 2026 |
35İzleyin | CVE-2026-44432İstismar yok | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming APIpython · urllib3 · CWE-409 | Yüksek8,9 | — | %0,9 | 13 May 2026 |
35İzleyin | CVE-2026-68981İstismar yok | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requestsapache · nifi · CWE-409 | Yüksek8,8 | — | %0,7 | 3 Ağu 2026 |
35İzleyin | CVE-2025-66471İstismar yok | urllib3 Streaming API improperly handles highly compressed datapython · urllib3 · CWE-409 | Yüksek8,9 | — | %0,7 | 5 Ara 2025 |
34İzleyin | CVE-2026-48586İstismar yok | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limitapache · thrift · CWE-409 | Yüksek8,7 | — | %1,0 | 27 Tem 2026 |
34İzleyin | CVE-2026-40036İstismar yok | Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompressionryandfir · unfurl · CWE-409 | Yüksek8,7 | — | %0,8 | 8 Nis 2026 |
34İzleyin | CVE-2026-82520İstismar yok | parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachmentsdomainaware · parsedmarc · CWE-409 | Yüksek8,7 | — | %0,8 | 3 Eyl 2026 |
34İzleyin | CVE-2026-59803İstismar yok | rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocolsmallnest · rpcx · CWE-409 | Yüksek8,7 | — | %0,7 | 8 Tem 2026 |
34İzleyin | CVE-2026-92000İstismar yok | adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Sizecthackers · adm-zip · CWE-409 | Yüksek8,7 | — | %0,7 | 15 Eyl 2026 |
34İzleyin | CVE-2026-78206İstismar yok | exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompressionexceljs · exceljs · CWE-409 | Yüksek8,7 | — | %0,6 | 23 Ağu 2026 |
34İzleyin | CVE-2026-75936İstismar yok | Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-javaamazon ion · amazon ion java · CWE-409 | Yüksek8,7 | — | %0,6 | 18 Ağu 2026 |
34İzleyin | CVE-2026-85786İstismar yok | Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-javaamazon · ion-java · CWE-409 | Yüksek8,7 | — | %0,6 | 4 Eyl 2026 |
34İzleyin | CVE-2026-62963İstismar yok | Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transportcentrifugal · centrifugo · CWE-409 | Yüksek8,7 | — | %0,5 | 16 Tem 2026 |
34İzleyin | CVE-2026-77620İstismar yok | Vector: Unauthenticated denial of service in the `logstash` source via nested compressed frames (stack exhaustion and decompression amplification).vectordotdev · vector · CWE-409 | Yüksek8,7 | — | %0,5 | 22 Eyl 2026 |
34İzleyin | CVE-2026-53430İstismar yok | grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1elixir-grpc · grpc · CWE-409 | Yüksek8,7 | — | %0,5 | 15 Haz 2026 |
34İzleyin | CVE-2026-44697İstismar yok | Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payloadklever-io · klever-go · CWE-409 | Yüksek8,6 | — | %0,5 | 29 May 2026 |
34İzleyin | CVE-2026-22776İstismar yok | cpp-httplib vulnerable to a denial of service (DOS) using a zip bombyhirose · cpp-httplib · CWE-409 | Yüksek8,7 | — | %0,4 | 12 Oca 2026 |
34İzleyin | CVE-2026-55195İstismar yok | py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction sizemiurahr · py7zr · CWE-409 | Yüksek8,7 | — | %0,3 | 8 Tem 2026 |
34İzleyin | CVE-2026-68911İstismar yok | Nicotine+: Decompression of peer messages can exhaust available memorynicotine-plus · nicotine-plus · CWE-409 | Yüksek8,7 | — | — | Bugün |
32İzleyin | CVE-2026-48594İstismar yok | Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compressionelixir-tesla · tesla · CWE-409 | Yüksek8,2 | — | %0,7 | 2 Haz 2026 |
32İzleyin | CVE-2026-49755İstismar yok | Decompression bomb DoS in Req via auto-decoded archive and compressed response bodieswojtekmach · req · CWE-409 | Yüksek8,2 | — | %0,7 | 8 Haz 2026 |
32İzleyin | CVE-2026-43970İstismar yok | Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frameninenines · cowlib · CWE-409 | Yüksek8,2 | — | %0,6 | 13 May 2026 |
32İzleyin | CVE-2026-54556İstismar yok | Http4s: HTTP/2 Denial of Service with Ember Backendhttp4s · http4s · CWE-409 | Yüksek8,2 | — | %0,5 | 26 Ağu 2026 |
32İzleyin | CVE-2026-44981İstismar yok | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompressioncrowdsecurity · crowdsec · CWE-409 | Yüksek8,2 | — | %0,5 | 16 Tem 2026 |
32İzleyin | CVE-2026-67232İstismar yok | RabbitMQ: Web-MQTT decompression bombrabbitmq · rabbitmq-server · CWE-409 | Yüksek8,2 | — | %0,4 | 6 gün önce |
- CVE-2026-2144136İzleyin
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
YüksekCVSS 8,9İstismar yokEPSS %3python · urllib37 Oca 2026
- CVE-2026-4443235İzleyin
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
YüksekCVSS 8,9İstismar yokEPSS %1python · urllib313 May 2026
- CVE-2026-6898135İzleyin
Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
YüksekCVSS 8,8İstismar yokEPSS %1apache · nifi3 Ağu 2026
- CVE-2025-6647135İzleyin
urllib3 Streaming API improperly handles highly compressed data
YüksekCVSS 8,9İstismar yokEPSS %1python · urllib35 Ara 2025
- CVE-2026-4858634İzleyin
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
YüksekCVSS 8,7İstismar yokEPSS %1apache · thrift27 Tem 2026
- CVE-2026-4003634İzleyin
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
YüksekCVSS 8,7İstismar yokEPSS %1ryandfir · unfurl8 Nis 2026
- CVE-2026-8252034İzleyin
parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
YüksekCVSS 8,7İstismar yokEPSS %1domainaware · parsedmarc3 Eyl 2026
- CVE-2026-5980334İzleyin
rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
YüksekCVSS 8,7İstismar yokEPSS %1smallnest · rpcx8 Tem 2026
- CVE-2026-9200034İzleyin
adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size
YüksekCVSS 8,7İstismar yokEPSS %1cthackers · adm-zip15 Eyl 2026
- CVE-2026-7820634İzleyin
exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
YüksekCVSS 8,7İstismar yokEPSS %1exceljs · exceljs23 Ağu 2026
- CVE-2026-7593634İzleyin
Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java
YüksekCVSS 8,7İstismar yokEPSS %1amazon ion · amazon ion java18 Ağu 2026
- CVE-2026-8578634İzleyin
Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
YüksekCVSS 8,7İstismar yokEPSS %1amazon · ion-java4 Eyl 2026
- CVE-2026-6296334İzleyin
Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport
YüksekCVSS 8,7İstismar yokEPSS %1centrifugal · centrifugo16 Tem 2026
- CVE-2026-7762034İzleyin
Vector: Unauthenticated denial of service in the `logstash` source via nested compressed frames (stack exhaustion and decompression amplification).
YüksekCVSS 8,7İstismar yokEPSS %1vectordotdev · vector22 Eyl 2026
- CVE-2026-5343034İzleyin
grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
YüksekCVSS 8,7İstismar yokEPSS %1elixir-grpc · grpc15 Haz 2026
- CVE-2026-4469734İzleyin
Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
YüksekCVSS 8,6İstismar yokEPSS %0klever-io · klever-go29 May 2026
- CVE-2026-2277634İzleyin
cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
YüksekCVSS 8,7İstismar yokEPSS %0yhirose · cpp-httplib12 Oca 2026
- CVE-2026-5519534İzleyin
py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
YüksekCVSS 8,7İstismar yokEPSS %0miurahr · py7zr8 Tem 2026
- CVE-2026-6891134İzleyin
Nicotine+: Decompression of peer messages can exhaust available memory
YüksekCVSS 8,7İstismar yoknicotine-plus · nicotine-plusBugün
- CVE-2026-4859432İzleyin
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
YüksekCVSS 8,2İstismar yokEPSS %1elixir-tesla · tesla2 Haz 2026
- CVE-2026-4975532İzleyin
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
YüksekCVSS 8,2İstismar yokEPSS %1wojtekmach · req8 Haz 2026
- CVE-2026-4397032İzleyin
Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame
YüksekCVSS 8,2İstismar yokEPSS %1ninenines · cowlib13 May 2026
- CVE-2026-5455632İzleyin
Http4s: HTTP/2 Denial of Service with Ember Backend
YüksekCVSS 8,2İstismar yokEPSS %1http4s · http4s26 Ağu 2026
- CVE-2026-4498132İzleyin
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
YüksekCVSS 8,2İstismar yokEPSS %1crowdsecurity · crowdsec16 Tem 2026
- CVE-2026-6723232İzleyin
RabbitMQ: Web-MQTT decompression bomb
YüksekCVSS 8,2İstismar yokEPSS %0rabbitmq · rabbitmq-server6 gün önce