Description
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 17 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. | |
| Title | snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress | |
| First Time appeared |
Xerial
Xerial snappy-java |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xerial
Xerial snappy-java |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T23:25:12.257Z
Reserved: 2026-09-17T22:45:30.909Z
Link: CVE-2026-93452
No data.
Status : Received
Published: 2026-09-18T00:17:49.540
Modified: 2026-09-18T00:17:49.540
Link: CVE-2026-93452
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-787
Out-of-bounds Write