PT-2026-108937 · Xerial · Snappy-Java
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
xerial snappy-java versions prior to 1.1.10.9
Description
An unbounded memory allocation issue exists where attackers can exhaust JVM memory by declaring a large uncompressed length in compressed input. By providing crafted bytes to the
uncompress(), uncompressString(), SnappyInputStream, or SnappyFramedInputStream functions, an attacker can force allocations up to 2 GB, leading to an OutOfMemoryError and a denial of service.Recommendations
Update xerial snappy-java to version 1.1.10.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snappy-Java