VYPR

CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)

BaseIncomplete

Description

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (97)

page 3 of 5
  • CVE-2025-62708HigOct 22, 2025
    risk 0.42cvss 7.5epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing the content stream of a page using the LZWDecode filter. This has been fixed in pypdf…

  • CVE-2025-60790MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.00

    ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

  • CVE-2025-58057HigSep 4, 2025
    risk 0.42cvss 7.5epss 0.01

    Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with…

  • CVE-2024-55909MedMay 2, 2025
    risk 0.42cvss 6.5epss 0.00

    IBM Concert Software 1.0.0 through 1.0.5 could allow an authenticated user to cause a denial of service due to the expansion of archive files without controlling resource consumption.

  • CVE-2025-32949MedApr 15, 2025
    risk 0.42cvss 6.5epss 0.01

    This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb. If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the…

  • CVE-2024-12387MedMar 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an…

  • CVE-2025-30153HigMar 19, 2025
    risk 0.42cvss 7.5epss 0.01

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available…

  • CVE-2024-3572HigApr 16, 2024
    risk 0.42cvss 7.5epss 0.01

    The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate…

  • CVE-2024-28101HigMar 21, 2024
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router…

  • CVE-2023-0821MedFeb 16, 2023
    risk 0.42cvss 6.5epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.

  • CVE-2022-45198HigNov 14, 2022
    risk 0.42cvss 7.5epss 0.01

    Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

  • CVE-2025-59472MedJan 26, 2026
    risk 0.38cvss 5.9epss 0.00

    A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume endpoint accepts unauthenticated POST requests with the `Next-Resume: 1` header and processes attacker-controlled postponed state…

  • CVE-2017-16129MedJun 7, 2018
    risk 0.38cvss 5.9epss 0.02

    The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may…

  • CVE-2025-46730MedMay 5, 2025
    risk 0.37cvss 6.8epss 0.00

    MobSF is a mobile application security testing tool used. Typically, MobSF is deployed on centralized internal or cloud-based servers that also host other security tools and web applications. Access to the MobSF web interface is often granted to internal security teams, audit…

  • CVE-2025-66019MedNov 26, 2025
    risk 0.36cvss epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This…

  • CVE-2022-37439MedAug 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file using the file monitoring input can result in a crash of the application. Attempts to restart the application would result in a crash and would require manually…

  • CVE-2026-14298MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when processing certain user-supplied input, which allows an authenticated user to cause a denial of service. Mattermost Advisory ID:…

  • CVE-2026-55497MedJul 31, 2026
    risk 0.35cvss 6.5epss 0.01

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers…

  • CVE-2026-10819MedJul 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF…

  • CVE-2026-54233MedJun 22, 2026
    risk 0.35cvss 6.5epss 0.00

    vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but not decoded PCM output. A 25MB OPUS file expands to ~14.9GB of float32 PCM at decode time. This vulnerability…