PT-2026-95188 · Unknown · Snappy-Java

·

CVE-2026-93451

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions snappy-java versions prior to 1.1.10.9
Description A buffer overflow exists in typed Snappy.uncompress*Array methods. The issue occurs because output arrays are allocated by dividing the uncompressed length by the element size, but the undivided length is passed to the native code. An attacker providing malicious compressed input can cause misaligned length values, leading to writes past array bounds and corruption of heap memory.
Recommendations Update to version 1.1.10.9 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93451

Affected Products

Snappy-Java