Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-409
Weakness type CWE-409 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 98 | 98 | 0 |
Monthly trend
▁▁▂▁▁▄▆▅█▂
2026-01 2 · 2026-02 0 · 2026-03 4 · 2026-04 2 · 2026-05 2 · 2026-06 13 · 2026-07 21 · 2026-08 18 · 2026-09 32 · 2026-10 4
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-49975 | 7.5 | 90.6 | — | Apache HTTP Server: mod_http2 denial of service |
| CVE-2026-21441 | 8.9 | 86.6 | — | urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects… |
| CVE-2026-75047 | 6.5 | 67.0 | — | — |
| CVE-2026-1526 | 7.5 | 65.8 | — | undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-def… |
| CVE-2026-48586 | 8.7 | 62.5 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-41608 | 7.5 | 62.5 | — | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport |
| CVE-2026-49158 | 7.5 | 62.5 | — | Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb |
| CVE-2026-29785 | 7.5 | 60.7 | — | NATS Server panic via malicious compression on leafnode port |
| CVE-2026-15709 | 7.5 | 57.8 | — | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded… |
| CVE-2026-44432 | 8.9 | 57.7 | — | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| CVE-2026-69304 | 5.9 | 57.6 | — | ASP.NET Core Denial of Service Vulnerability |
| CVE-2026-40192 | 8.7 | 57.3 | — | Pillow is vulnerable to a FITS GZIP decompression bomb |
| CVE-2026-46387 | 7.5 | 56.9 | — | Suricata http2: decompression bomb can cause denial of service in Suricata |
| CVE-2026-89059 | 7.5 | 54.8 | — | Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos) |
| CVE-2026-40036 | 8.7 | 54.7 | — | Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression |
| CVE-2026-82520 | 8.7 | 54.5 | — | parsedmarc < 11.0.1 Zip Bomb DoS via Compressed Email Attachments |
| CVE-2026-59803 | 8.7 | 53.1 | — | rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol |
| CVE-2026-83599 | 7.5 | 53.1 | — | Netdata: WebSocket Decompression Bomb |
| CVE-2026-68981 | 8.8 | 53.0 | — | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests |
| CVE-2026-24264 | 7.5 | 52.3 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 11 |
| getgrav | 4 |
| mattermost | 4 |
| red hat | 3 |
| aio-libs | 2 |
| elastic | 2 |
| fluent | 2 |
| messagepack-csharp | 2 |
| oisf | 2 |
| tanium | 2 |
| tornadoweb | 2 |
| urllib3 | 2 |
| vllm-project | 2 |
| amazon | 1 |
| amazon ion | 1 |