Description
snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.
Published: 2026-09-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

snappy-java versions up to 1.1.10.8 contain an out‑of‑bounds write vulnerability in the uncompress(ByteBuffer, ByteBuffer) method because the destination buffer’s capacity is never checked against the decompressed size. An attacker can supply a crafted compressed payload that expands beyond the buffer, causing data to be written past the end of the buffer. This memory corruption will result in a JVM crash and effectively deny service to the affected application. The weakness is a classic buffer overflow, classified under CWE-787.

Affected Systems

All releases of Xerial’s snappy-java library through 1.1.10.8 are vulnerable. Any software that incorporates this library—such as data processing frameworks, big‑data pipelines, or custom services—could be impacted if it ever processes untrusted compressed data.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of < 1% suggests a very low yet non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via delivery of malicious compressed data to the uncompress method; this could be invoked either locally or remotely by any component that accepts externally sourced compressed streams. Based on the description it is inferred that an attacker can trigger the fault by supplying crafted data to the vulnerable method.

Generated by OpenCVE AI on September 15, 2026 at 17:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade snappy-java to version 1.1.10.9 or later to apply the buffer‑size validation fix.
  • If an upgrade is infeasible, add a guard that validates the declared decompressed length against the destination buffer’s capacity before calling uncompress, rejecting or truncating payloads that would exceed the buffer.
  • Implement a maximum decompression size limit or use a wrapper that checks payload size before invoking the library to prevent the out‑of‑bounds write condition.

Generated by OpenCVE AI on September 15, 2026 at 17:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.
Title snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress
First Time appeared Xerial
Xerial snappy-java
Weaknesses CWE-787
CPEs cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*
Vendors & Products Xerial
Xerial snappy-java
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Xerial Snappy-java
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:16:09.264Z

Reserved: 2026-09-12T11:13:43.326Z

Link: CVE-2026-90559

cve-icon Vulnrichment

Updated: 2026-09-14T17:06:14.587Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-12T18:16:44.743

Modified: 2026-09-24T20:28:01.780

Link: CVE-2026-90559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses