{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3axerialsnappy-java/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108106"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["snappy-java (\u003c 1.1.10.9)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Xerial"],"content_html":"\u003cp\u003eThe snappy-java library versions prior to 1.1.10.9 are susceptible to an unbounded memory allocation vulnerability (CVE-2026-108106). This flaw occurs when the library processes compressed input, as it fails to properly validate the uncompressed length declared in the data. An attacker can supply a small amount of specially crafted input to functions such as Snappy.uncompress, uncompressString, SnappyInputStream, or SnappyFramedInputStream.\u003c/p\u003e\n\u003cp\u003eWhen processed, these crafted inputs force the library to attempt memory allocations of up to 2 GB. This behavior leads to an immediate OutOfMemoryError within the Java Virtual Machine (JVM), resulting in a denial-of-service (DoS) condition. Because snappy-java is a core dependency for many high-performance data processing frameworks and database connectors, this vulnerability presents a significant risk to the availability of Java-based services that process untrusted or externally sourced data streams.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in an immediate denial-of-service condition due to JVM exhaustion. Systems heavily reliant on snappy-java for deserialization or data stream processing across various enterprise sectors are at risk. If exploited against critical infrastructure or high-availability microservices, this can lead to widespread service disruption, requiring manual intervention or process restarts to restore operation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the snappy-java library to version 1.1.10.9 or later across all applications and dependencies.\u003c/li\u003e\n\u003cli\u003eReview software bills of materials (SBOMs) to identify all instances of snappy-java in the environment.\u003c/li\u003e\n\u003cli\u003eApply the patch for CVE-2026-108106 to any internet-facing or ingestion services that process external input through this library.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T15:32:24Z","date_published":"2026-10-09T15:32:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-snappy-java-dos/","summary":"The snappy-java library prior to version 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to trigger a JVM OutOfMemoryError via crafted input.","title":"Unbounded Memory Allocation in Xerial snappy-java","url":"https://feed.craftedsignal.io/briefs/2026-10-snappy-java-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:xerial:snappy-Java:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}