CWE-409: Data Amplification
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
106 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-66471 — urllib3 Streaming API improperly handles highly compressed data
- CVE-2026-22776 — cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
- CVE-2026-14298 — Denial of service via resource exhaustion in Mattermost
- CVE-2026-10819 — Mattermost Server Denial of Service via Animated GIF Emoji Upload
- CVE-2026-21441 — urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
- CVE-2026-28435 — Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies in cpp-httplib
- CVE-2025-30153 — Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
- CVE-2024-28101 — Apollo Router's Compressed Payloads do not respect HTTP Payload Limits
- CVE-2024-12886 — Out-Of-Memory (OOM) Vulnerability in ollama/ollama
- CVE-2026-44432 — urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
- CVE-2026-68981 — Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
- CVE-2026-40036 — Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
- CVE-2026-78206 — exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
- CVE-2026-62963 — Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport
- CVE-2026-53430 — grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/1
- CVE-2026-85786 — Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
- CVE-2026-82520 — parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
- CVE-2026-75936 — Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java
- CVE-2026-59803 — rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol
- CVE-2026-55195 — py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
Recently published
- CVE-2026-79695 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-85786 — Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
- CVE-2026-82520 — parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments
- CVE-2026-84382 — HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification)
- CVE-2026-78594 — Improper Handling of Highly Compressed Data in APM Server Leading to Persistent Denial of Service
- CVE-2026-72628 — Improper Handling of Highly Compressed Data in Kibana Leading to Denial of Service
- CVE-2026-82864 — pdfme pdf-lib before 5.5.10 Denial of Service via Decompression Bomb
- CVE-2026-58107 — Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun
- CVE-2026-54556 — Http4s: HTTP/2 Denial of Service with Ember Backend
- CVE-2026-80189 — LeafWiki 0.10.0 through 0.12.0 Uncontrolled Resource Consumption via Unbounded ZIP Extraction
- CVE-2026-78206 — exceljs through 4.4.0 Uncontrolled Resource Consumption via Unbounded xlsx Decompression
- CVE-2026-53524 — WeeChat has a Decompression Bomb in Relay WebSocket (DoS)
- CVE-2026-11617 — Tanium addressed a compression bomb vulnerability in Findings.
- CVE-2026-75476 — Tanium addressed a compression bomb vulnerability in Threat Response.
- CVE-2026-61690 — Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
- CVE-2026-75936 — Memory-amplification denial of service via GZIP decompression bomb in Amazon ion-java
- CVE-2026-19671 — Improper handling of highly compressed data (data amplification) in CISA Malcolm
- CVE-2026-74046 — Wazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip Bomb
- CVE-2026-18929 — Resource Exhaustion in Carbone
- CVE-2026-75047 — In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint