Description
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

snappy-java versions up to 1.1.10.8 contain a buffer overflow in the Snappy.compress method. The vulnerability allows an attacker to write beyond the end of the destination ByteBuffer, corrupting off‑heap memory. This corruption can terminate the JVM.

Affected Systems

xerial's snappy-java library, versions up to 1.1.10.8, is affected by the buffer overflow. This includes any Java application that incorporates the vulnerable library and uses the Snappy.compress method on ByteBuffer inputs.

Risk and Exploitability

With a CVSS score of 8.7 the vulnerability is considered high severity, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the overflow by supplying incompressible data that exceeds the destination buffer's remaining capacity, a scenario that is inferred to occur when the application processes data that may be under the attacker's control.

Generated by OpenCVE AI on September 19, 2026 at 08:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a snappy-java release that contains the buffer overflow fix.
  • If an upgrade is not possible, validate the size of the source data before calling Snappy.compress to ensure it fits within the remaining capacity of the destination buffer.
  • Avoid processing untrusted data with Snappy.compress; consider rejecting or sanitizing input streams that have a high compression ratio.
  • Apply security runtime controls to isolate or restrict the Java process using the vulnerable library, mitigating potential memory corruption impact.

Generated by OpenCVE AI on September 19, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
Title snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress
First Time appeared Xerial
Xerial snappy-java
Weaknesses CWE-787
CPEs cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*
Vendors & Products Xerial
Xerial snappy-java
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Xerial Snappy-java
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T15:51:53.110Z

Reserved: 2026-09-17T22:45:30.909Z

Link: CVE-2026-93452

cve-icon Vulnrichment

Updated: 2026-09-18T20:00:22.852Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T00:17:49.540

Modified: 2026-10-08T16:18:00.507

Link: CVE-2026-93452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses