Impact
A flaw in HdrHistogram’s recordValueWithCount method allows an attacker to supply a malicious count value that corrupts the histogram’s internal state. The resulting state fault manifests as inaccurate statistics or unexpected failures in downstream components that rely on the data. The weakness is classified as CWE‑371,
Affected Systems
All releases of HdrHistogram up to and including version 2.2.2 are affected. The vulnerability is fixed in future releases, so any deployment that incorporates an earlier version remains susceptible until the flaw is patched.
Risk and Exploitability
The CVSS score of 4.8 indicates low severity, and the EPSS score of < 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and can only be abused from a local environment. Thus the risk is confined to local execution.
OpenCVE Enrichment