CVE-2026-102554: Google Guava

High severity, CVSS 8.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

Affected products

  • Google Guava: from 4.0, before 33.7.2 (fixed in 33.7.2)

Published 2026-10-09. Last modified 2026-10-09.