<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Snappy-Java (&lt; 1.1.10.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/snappy-java--1.1.10.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 15:32:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/snappy-java--1.1.10.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unbounded Memory Allocation in Xerial snappy-java</title><link>https://feed.craftedsignal.io/briefs/2026-10-snappy-java-dos/</link><pubDate>Fri, 09 Oct 2026 15:32:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-snappy-java-dos/</guid><description>The snappy-java library prior to version 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to trigger a JVM OutOfMemoryError via crafted input.</description><content:encoded><![CDATA[<p>The snappy-java library versions prior to 1.1.10.9 are susceptible to an unbounded memory allocation vulnerability (CVE-2026-108106). This flaw occurs when the library processes compressed input, as it fails to properly validate the uncompressed length declared in the data. An attacker can supply a small amount of specially crafted input to functions such as Snappy.uncompress, uncompressString, SnappyInputStream, or SnappyFramedInputStream.</p>
<p>When processed, these crafted inputs force the library to attempt memory allocations of up to 2 GB. This behavior leads to an immediate OutOfMemoryError within the Java Virtual Machine (JVM), resulting in a denial-of-service (DoS) condition. Because snappy-java is a core dependency for many high-performance data processing frameworks and database connectors, this vulnerability presents a significant risk to the availability of Java-based services that process untrusted or externally sourced data streams.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in an immediate denial-of-service condition due to JVM exhaustion. Systems heavily reliant on snappy-java for deserialization or data stream processing across various enterprise sectors are at risk. If exploited against critical infrastructure or high-availability microservices, this can lead to widespread service disruption, requiring manual intervention or process restarts to restore operation.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for engineering and security teams:</p>
<ul>
<li>Upgrade the snappy-java library to version 1.1.10.9 or later across all applications and dependencies.</li>
<li>Review software bills of materials (SBOMs) to identify all instances of snappy-java in the environment.</li>
<li>Apply the patch for CVE-2026-108106 to any internet-facing or ingestion services that process external input through this library.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>