boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-409

Weakness type CWE-409 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
49490

Monthly trend

▂▁▂▁▂▅█▄

2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 2 · 2026-06 13 · 2026-07 21 · 2026-08 9

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2026-214418.984.8urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects…
CVE-2026-15267.564.3undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-def…
CVE-2026-416087.563.0Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
CVE-2026-491587.563.0Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb
CVE-2026-485868.762.3Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif…
CVE-2026-477747.559.0Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK am…
CVE-2026-750476.555.7
CVE-2026-599327.550.0PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-444328.949.6urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
CVE-2026-239436.948.1Pre-auth SSH DoS via unbounded zlib inflate
CVE-2026-497558.245.9Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
CVE-2026-498557.544.8tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
CVE-2026-157097.543.6Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded…
CVE-2026-554976.542.6Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar de…
CVE-2026-189296.942.0Resource Exhaustion in Carbone
CVE-2026-689818.841.8Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests
CVE-2025-692237.541.1AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
CVE-2026-242647.539.6
CVE-2026-485948.237.9Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
CVE-2026-732327.537.3ffuf denial of service (OOM) via HTTP response decompression bomb

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
apache4
getgrav4
aio-libs2
envoyproxy2
mattermost2
messagepack-csharp2
urllib32
amazon ion1
carbone1
centrifugal1
cisagov1
cloudreve1
coder1
crowdsecurity1
crux1