CVE-2026-102554

EUVD-2026-95889
Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GoogleCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.82%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
googleguava
4.0 ≤
𝑥
< 33.7.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
guava-libraries
bookworm
vulnerable
forky
vulnerable
sid
vulnerable
trixie
vulnerable