HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza s
gosaml2 is a Pure Go implementation of SAML 2.0. SAML Service Providers using this library for SAML authentication suppo
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data i
In Splunk Enterprise and Universal Forwarder versions in the following table, indexing a specially crafted ZIP file usin
The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with
Frequently Asked Questions
What is CWE-409?
CWE-409 (CWE-409) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-409?
There are 109 CVE records associated with CWE-409 in our database. Of these, 1 are critical severity, 46 are high severity, and 45 are medium severity.
How can I protect against CWE-409 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-409 using AI-powered security agents.
Detect CWE-409 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-409 vulnerabilities across your infrastructure.
Get Started