Description
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory.
Published: 2026-09-17
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

snappy-java versions up to 1.1.10.8 contain a buffer overflow in the typed Snappy.uncompress*Array methods. The methods allocate output arrays by dividing the reported uncompressed length by the element size, yet they pass the full uncompressed length to the native decompression routine. An attacker can craft compressed input that contains a length value misaligned with the element size, causing the native code to write past the array boundaries. This heap corruption can lead to arbitrary code execution if the application processes attacker‑controlled compressed data. The vulnerability is specifically within the native code invoked by Java, so the impact manifests as a failure of memory safety within a Java process that can be leveraged to execute code. The nature of the flaw is a classic buffer overflow (CWE-787) caused by improper bounds checking between Java and native layers, coupled with memory reuse and alignment issues (CWE-131) arising from dividing uncompressed length by element size while passing the undivided length to native code.

Affected Systems

The vulnerability affects the snappy-java library released by xerial. All releases up through 1.1.10.8 are affected; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 6.9 indicates a Medium severity vulnerability. The EPSS score is below 1 %, suggesting a low probability that exploit code will be seen in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application to invoke the vulnerable native uncompress*Array methods with attacker‑controlled compressed input. If the application runs with sufficient privileges, a successful exploitation could give an attacker arbitrary code execution on the host. The description does not mention network reachability, so the most likely attack vector is an application that accepts externally supplied compressed data, such as a remote service or file upload endpoint.

Generated by OpenCVE AI on October 1, 2026 at 20:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade snappy-java to a fixed release newer than 1.1.10.8.
  • If upgrading is not immediately possible, remove or refactor any code that passes untrusted compressed data to the Snappy.uncompress*Array methods; instead perform strict validation or refuse decompression of data that could trigger the overflow.
  • Implement additional input validation to reject malformed or oversized compressed payloads before they reach the native code, ensuring that lengths passed to native methods are within acceptable bounds.

Generated by OpenCVE AI on October 1, 2026 at 20:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory.
Title snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods
First Time appeared Xerial
Xerial snappy-java
Weaknesses CWE-787
CPEs cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*
Vendors & Products Xerial
Xerial snappy-java
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Xerial Snappy-java
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:52:30.715Z

Reserved: 2026-09-17T22:45:30.561Z

Link: CVE-2026-93451

cve-icon Vulnrichment

Updated: 2026-09-21T16:28:45.579Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T00:17:49.380

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93451

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T23:25:11Z

Links: CVE-2026-93451 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:45:12Z

Weaknesses
  • CWE-131

    Incorrect Calculation of Buffer Size

  • CWE-787

    Out-of-bounds Write