CVE-2026-108104
EUVD-2026-9580609.10.2026, 15:17
Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| xerial | snappy-java | 1.1.7.4 ≤ 𝑥 < 1.1.10.10 | CNA |
Debian Releases
Common Weakness Enumeration
References