CVE-2026-108104
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-108104, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xerial snappy-java 1.1.7.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-415 The product calls free() twice on the same memory address.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Xerial snappy-java versions 1.1.7.4 to 1.1.10.10 involves a double release issue in SnappyFramedInputStream where pooled buffers are returned twice if replacement allocation fails. Attackers can exploit this by sending framed data with an abnormally large chunk length, causing an OutOfMemoryError and exposing or overwriting decompressed data from other streams.

Detection Guidance

To detect this vulnerability, check if your system uses snappy-java versions 1.1.7.4 through 1.1.10.9. Run commands like 'mvn dependency:tree' for Maven or 'gradle dependencies' for Gradle to inspect dependencies. If vulnerable versions are found, update to 1.1.10.10 or later.

Impact Analysis

This vulnerability can lead to denial of service via OutOfMemoryError, data leaks where sensitive information from one stream is exposed to another, or potential data corruption if attackers overwrite decompressed data. Systems processing untrusted framed data are at higher risk.

Compliance Impact

This vulnerability could violate GDPR or HIPAA by enabling unauthorized access to or leakage of sensitive data (e.g., personal or health information) due to shared buffer exposure. Organizations must address this to maintain data confidentiality and compliance.

Mitigation Strategies

Upgrade snappy-java to version 1.1.10.10 or later to address the double release vulnerability in SnappyFramedInputStream.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108104. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart