CVE-2018-10237: Google Guava
Medium severity, CVSS 5.9. EPSS: 5.1% chance of exploitation in the next 30 days.
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Affected products
- Google Guava: from 11.0, before 24.1.1 (fixed in 24.1.1)
- Oracle Banking Payments: from 14.1.0, up to and including 14.4.0
- Oracle Communications IP Service Activator: version 7.3.0 only; version 7.4.0 only
- Oracle Customer Management And Segmentation Foundation: version 18.0 only
- Oracle Database Server: version 12.2.0.1 only; version 18c only; version 19c only
- Oracle Flexcube Investor Servicing: version 12.1.0 only; version 12.3.0 only; version 12.4.0 only; version 14.0.0 only; version 14.1.0 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Retail Integration Bus: version 15.0 only; version 16.0 only
- Oracle Retail Xstore Point Of Service: version 7.1 only; version 15.0 only; version 16.0 only; version 17.0 only
- Oracle WebLogic Server: version 12.2.1.3.0 only
- Red Hat JBoss Enterprise Application Platform: version 6.0.0 only; version 6.4.0 only; version 7.1.0 only
- Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only
- Red Hat Openstack: version 13 only
- Red Hat Satellite: version 6.4 only
- Red Hat Satellite Capsule: version 6.4 only
- Red Hat Virtualization: version 4.2 only; version 4.0 only
- Red Hat Virtualization Host: version 4.0 only
Published 2018-04-26. Last modified 2026-06-17.