Skip to content
CVE Alert: CVE-2026-108106 – xerial – snappy

CVE Alert: CVE-2026-108106 – xerial – snappy

Redpacketsecurity •admin • October 9, 2026

Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service.

**Risk verdict:** High availability risk where untrusted compressed data reaches affected Java services; exploitation urgency cannot be ranked because KEV, SSVC and EPSS status were not provided.

**Why this matters:** A crafted input can exhaust the JVM’s memory, potentially interrupting the service and triggering repeated restarts. Attackers could target exposed ingestion or processing functions to cause outages, disrupt dependent workloads, or consume operational resources; confidentiality and integrity impact is not indicated.

**Most likely attack path:** The network-facing path requires no special privileges, user action or complex conditions, making any reachable decode function a concern. Scope is unchanged, so the direct impact is to the vulnerable service rather than inherently enabling lateral movement.

**Who is most exposed:** Prioritise Java applications that decode Snappy data from external clients, message brokers, uploaded files or inter-service feeds, including services using the library transitively.

Alert on JVM `OutOfMemoryError`, abrupt process exits and repeated container or service restarts.

Correlate memory spikes with requests or messages entering Snappy decode paths.

Review application and dependency inventories for the affected library and trace whether untrusted data reaches decompression.

Mitigation and prioritisation

Upgrade to the vendor-fixed release; prioritise internet-reachable and business-critical consumers.

Until upgraded, reject or isolate untrusted Snappy input and apply strict payload and resource limits where feasible.

Test representative compressed-data workflows, then roll out through normal change controls with rollback monitoring.

Obtain KEV, SSVC, EPSS and PoC status before final urgency ranking; treat as priority 1 if KEV is true or EPSS is at least 0.5.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

IP Addresses (1)

Platforms (2)