snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. | |
| Title | snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress | |
| First Time appeared |
Xerial
Xerial snappy-java |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xerial
Xerial snappy-java |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T23:25:12.257Z
Reserved: 2026-09-17T22:45:30.909Z
Link: CVE-2026-93452
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses