Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-409 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 49 | 49 | 0 |
▂▁▂▁▂▅█▄
2026-01 2 · 2026-02 0 · 2026-03 2 · 2026-04 0 · 2026-05 2 · 2026-06 13 · 2026-07 21 · 2026-08 9
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-21441 | 8.9 | 84.8 | — | urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects… |
| CVE-2026-1526 | 7.5 | 64.3 | — | undici is vulnerable to Unbounded Memory Consumption in undici WebSocket permessage-def… |
| CVE-2026-41608 | 7.5 | 63.0 | — | Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport |
| CVE-2026-49158 | 7.5 | 63.0 | — | Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb |
| CVE-2026-48586 | 8.7 | 62.3 | — | Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrif… |
| CVE-2026-47774 | 7.5 | 59.0 | — | Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK am… |
| CVE-2026-75047 | 6.5 | 55.7 | — | — |
| CVE-2026-59932 | 7.5 | 50.0 | — | PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion |
| CVE-2026-44432 | 8.9 | 49.6 | — | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API |
| CVE-2026-23943 | 6.9 | 48.1 | — | Pre-auth SSH DoS via unbounded zlib inflate |
| CVE-2026-49755 | 8.2 | 45.9 | — | Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies |
| CVE-2026-49855 | 7.5 | 44.8 | — | tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) |
| CVE-2026-15709 | 7.5 | 43.6 | — | Soupwebsocketextensiondeflate: libsoup: libsoup: websocket permessage-deflate unbounded… |
| CVE-2026-55497 | 6.5 | 42.6 | — | Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar de… |
| CVE-2026-18929 | 6.9 | 42.0 | — | Resource Exhaustion in Carbone |
| CVE-2026-68981 | 8.8 | 41.8 | — | Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests |
| CVE-2025-69223 | 7.5 | 41.1 | — | AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb |
| CVE-2026-24264 | 7.5 | 39.6 | — | — |
| CVE-2026-48594 | 8.2 | 37.9 | — | Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression |
| CVE-2026-73232 | 7.5 | 37.3 | — | ffuf denial of service (OOM) via HTTP response decompression bomb |
| Vendor | CVEs |
|---|---|
| apache | 4 |
| getgrav | 4 |
| aio-libs | 2 |
| envoyproxy | 2 |
| mattermost | 2 |
| messagepack-csharp | 2 |
| urllib3 | 2 |
| amazon ion | 1 |
| carbone | 1 |
| centrifugal | 1 |
| cisagov | 1 |
| cloudreve | 1 |
| coder | 1 |
| crowdsecurity | 1 |
| crux | 1 |