Doesn't this mean that malicious inputs can deliberately cause super tiny or super huge chunks?

The same is true without CDC, and you can configure a maximum size.