Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service. | |
| Title | Xerial snappy-java before 1.1.10.9 Unbounded Memory Allocation Denial of Service | |
| First Time appeared |
Xerial
Xerial snappy-java |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xerial
Xerial snappy-java |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T14:33:29.499Z
Reserved: 2026-10-09T13:44:40.883Z
Link: CVE-2026-108106
No data.
Status : Received
Published: 2026-10-09T15:17:11.550
Modified: 2026-10-09T15:17:11.550
Link: CVE-2026-108106
No data.
OpenCVE Enrichment
Updated: 2026-10-09T15:30:08Z