CVE-2026-108106: Xerial Snappy-Java

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service.

Affected products

  • Xerial Snappy-Java: before 1.1.10.9 (fixed in 1.1.10.9)

Published 2026-10-09. Last modified 2026-10-09.