CVE-2026-108106
Received Received - Intake

Unbounded Memory Allocation in Snappy-Java

Vulnerability report for CVE-2026-108106, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: VulnCheck

Description

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
xerial snappy-java 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Xerial snappy-java before 1.1.10.9 allows attackers to cause an OutOfMemoryError by providing compressed input with a large uncompressed length. This forces the JVM to allocate up to 2 GB of memory, leading to denial of service.

Detection Guidance

Detecting this vulnerability requires checking for outdated versions of snappy-java. Use commands like 'find . -name "*.jar" -exec grep -l "snappy-java" {} \;' to locate snappy-java libraries. Verify versions with 'mvn dependency:tree' in Maven projects or 'gradle dependencies' in Gradle projects.

Impact Analysis

An attacker could exploit this to crash applications using snappy-java by sending maliciously crafted data, causing service disruption or system downtime. Systems with high availability requirements are particularly at risk.

Mitigation Strategies

Upgrade snappy-java to version 1.1.10.9 or later. For Maven projects, update the dependency in pom.xml. For Gradle, modify build.gradle. Remove any unused or outdated snappy-java dependencies to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108106. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart