CVE-2026-108106: Xerial Snappy-Java
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service.
Affected products
- Xerial Snappy-Java: before 1.1.10.9 (fixed in 1.1.10.9)
Published 2026-10-09. Last modified 2026-10-09.