Cyber Posture

CWE · MITRE source

CWE-409Improper Handling of Highly Compressed Data (Data Amplification)

Abstraction: Base · CVEs in our corpus: 47

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-5Denial-of-service ProtectionSCLimits effects of data amplification from compressed or malicious inputs.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2026-278091.89.10.00082026-02-26
CVE-2022-292251.57.50.00082022-06-09
CVE-2024-281011.57.50.00292024-03-21
CVE-2024-35721.57.50.00162024-04-16
CVE-2024-434991.57.50.00732024-11-12
CVE-2025-301531.57.50.00122025-03-19
CVE-2024-128861.57.50.00212025-03-20
CVE-2024-77651.57.50.00412025-03-20
CVE-2025-580571.57.50.00062025-09-04
CVE-2025-627081.57.50.00072025-10-22
CVE-2025-664711.57.50.00012025-12-05
CVE-2025-669091.57.50.00582025-12-19
CVE-2025-692231.57.50.00082026-01-05
CVE-2026-214411.57.50.00032026-01-07
CVE-2026-227761.57.50.00082026-01-12
CVE-2026-228701.57.50.00022026-01-13
CVE-2026-284351.57.50.00082026-03-04
CVE-2026-15261.57.50.00022026-03-12
CVE-2026-400361.57.50.00142026-04-08
CVE-2025-467301.46.80.00312025-05-05
CVE-2023-08211.36.50.00452023-02-16
CVE-2024-546821.36.50.00202024-12-16
CVE-2025-251861.36.50.00142025-02-10
CVE-2024-123871.36.50.00472025-03-20
CVE-2025-329491.36.50.00122025-04-15