Executive brief
HdrHistogram is a Java library used for recording and analyzing high dynamic range data, often used in performance monitoring. A flaw in how the library processes data from memory buffers could allow a local user to cause the application to crash by triggering excessive memory consumption. This could lead to a denial-of-service condition, impacting the availability of monitoring tools or applications using this library.
Technical details
A vulnerability classified as CWE-789 (Memory Allocation with Excessive Size Value) and CWE-400 (Uncontrolled Resource Consumption) exists in HdrHistogram up to version 2.2.2. The flaw is located in the `org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer` function within `src/main/java/org/HdrHistogram/AbstractHistogram.java`. By manipulating the `numberOfSignificantValueDigits` argument in a serialized buffer, a local attacker can trigger an Out-of-Memory (OOM) condition. While an exploit has been published, the project has not yet released a formal patch at the time of reporting. The attack requires local access and low privileges.
Affected products
- HdrHistogram HdrHistogram Up to 2.2.2
Timeline
- 2026-07-05: advisory: NVD publication date
- 2026-07-05: disclosed: Public disclosure of the vulnerability and exploit