CVE-2026-102554
Awaiting Analysis Awaiting Analysis - Queue

Denial of Service in Google Guava via Unbounded Deserialization

Vulnerability report for CVE-2026-102554, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Google Inc.

Description

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Google Guava 4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an allocation of resources without limits or throttling during Java object deserialization in Google Guava versions 4.0 through 33.7.1. It allows an attacker to cause a Denial of Service via OutOfMemoryError by crafting serialization streams that request abnormally large array sizes during deserialization of CompactHashMap, CompactHashSet, or MapMakerInternalMap instances.

Detection Guidance

To detect this vulnerability, check if your system uses Google Guava versions 4.0 through 33.7.1. Run commands like 'mvn dependency:tree' in Maven projects or 'gradle dependencies' in Gradle projects to inspect dependencies. Look for Guava versions within the affected range.

Impact Analysis

An attacker can exploit this to crash applications by forcing them to allocate excessive memory, leading to OutOfMemoryError. This can disrupt services, cause downtime, and require restarting affected systems. The attack requires no special privileges or user interaction and can be executed remotely if untrusted data is deserialized.

Compliance Impact

This vulnerability could lead to denial-of-service conditions via OutOfMemoryError, potentially disrupting services handling sensitive data. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Upgrade Google Guava to version 33.7.2 or later. Replace affected classes like MapMaker, CompactHashMap, CompactHashSet, CompactLinkedHashMap, CompactLinkedHashSet, and MapMakerInternalMap with alternatives or apply patches. Avoid deserializing untrusted data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102554. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart