CWE-409

CWE-409 · 9 records · 6 with a public proof-of-concept

Records the NVD classes under CWE-409, highest CVSS first.

  1. HIGH 7.5CVE-2026-83599public PoC

    Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow de…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-47321

    The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a compression ration greater …

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-85721public PoC

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 2.16.1 and 3.0.12, automatic response decompression on the HTTP/1.1 path uses ChannelManager.newHttpContentDe…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-92000public PoC

    adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause de…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 6.5CVE-2026-92573

    Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker a…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 6.5CVE-2026-65827public PoC

    Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an archive to the page-import feature whose ZIP extraction routine does not limit total un…

    AI risk analysis on Exploit-DB.ai →

  7. UNSCOREDCVE-2026-67232public PoC

    RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy WebSocket options at line 117 set compress => true, enabling RFC 7692 permessage-deflate negotiation. The handler does not set max_frame_size,…

    AI risk analysis on Exploit-DB.ai →

  8. UNSCOREDCVE-2026-77620public PoC

    Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that can reach the default 0.0…

    AI risk analysis on Exploit-DB.ai →

  9. UNSCOREDCVE-2026-77021

    Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib comp…

    AI risk analysis on Exploit-DB.ai →