Skip to content
High-Risk CVE-2026-108106 in Xerial Snappy Java Library

High-Risk CVE-2026-108106 in Xerial Snappy Java Library

First seen 9 Oct 2026, 20:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 21:38 UTC
  • •CVE-2026-108106 affects Xerial snappy-java versions before 1.1.10.9.
  • •The vulnerability allows attackers to exhaust JVM memory, leading to denial of service.
  • •Immediate upgrade to the patched version is recommended to mitigate risks.

Xerial snappy-java versions prior to 1.1.10.9 are vulnerable to an unbounded memory allocation flaw, identified as CVE-2026-108106, which can lead to denial of service by exhausting JVM memory. Attackers can exploit this vulnerability by supplying crafted input to various decoding functions, potentially causing OutOfMemoryError and service interruptions. The vulnerability poses a high availability risk, particularly for Java applications that decode Snappy data from untrusted sources. The current status indicates no confirmed exploitation in the wild, but the urgency for patching is emphasized. Users are advised to upgrade to the fixed version and implement strict input validation and resource limits until then. The CVSS score for this vulnerability is 8.7, categorizing it as high severity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
CVE-2026-108106 published
Xerial snappy-java vulnerability disclosed, affecting versions before 1.1.10.9 with a CVSS score of 8.7.
Redpacketsecurity
2026-10-09
Vulnerability advisory issued
Advisories recommend immediate patching and caution against untrusted Snappy input until fixed.
www.vulncheck.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-108106 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Xerial snappy-java versions prior to 1.1.10.9 are affected by this vulnerability.
What is the risk level of this vulnerability?
The CVSS score is 8.7, indicating a high severity risk for denial of service.
What should I do if I am using an affected version?
Upgrade to version 1.1.10.9 or later immediately and implement strict input validation.