www.vulncheck.com High-Risk CVE-2026-108106 in Xerial Snappy Java Library
Article Content
- •CVE-2026-108106 affects Xerial snappy-java versions before 1.1.10.9.
- •The vulnerability allows attackers to exhaust JVM memory, leading to denial of service.
- •Immediate upgrade to the patched version is recommended to mitigate risks.
Xerial snappy-java versions prior to 1.1.10.9 are vulnerable to an unbounded memory allocation flaw, identified as CVE-2026-108106, which can lead to denial of service by exhausting JVM memory. Attackers can exploit this vulnerability by supplying crafted input to various decoding functions, potentially causing OutOfMemoryError and service interruptions. The vulnerability poses a high availability risk, particularly for Java applications that decode Snappy data from untrusted sources. The current status indicates no confirmed exploitation in the wild, but the urgency for patching is emphasized. Users are advised to upgrade to the fixed version and implement strict input validation and resource limits until then. The CVSS score for this vulnerability is 8.7, categorizing it as high severity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-108106 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
What is the risk level of this vulnerability?
What should I do if I am using an affected version?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…