CWE-409: Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Overview
An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.
Real-world CVEs
43 recorded CVEs are caused by CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)). The highest-severity and most recent are shown first. 18 new CWE-409 CVEs have been recorded so far in 2026 (14 in 2025).