Junglewise Threat Intelligence

CVE-2026-14684: HdrHistogram uncontrolled memory allocation in AbstractHistogram

CVE-2026-14684 · Severity: low · CVSS 3.3 · Published 2026-07-05

Technologies: HdrHistogram. Vendors: HdrHistogram.

Executive brief

HdrHistogram is a Java library used for recording and analyzing high dynamic range data, often used in performance monitoring. A flaw in how the library processes data from memory buffers could allow a local user to cause the application to crash by triggering excessive memory consumption. This could lead to a denial-of-service condition, impacting the availability of monitoring tools or applications using this library.

Technical details

A vulnerability classified as CWE-789 (Memory Allocation with Excessive Size Value) and CWE-400 (Uncontrolled Resource Consumption) exists in HdrHistogram up to version 2.2.2. The flaw is located in the `org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer` function within `src/main/java/org/HdrHistogram/AbstractHistogram.java`. By manipulating the `numberOfSignificantValueDigits` argument in a serialized buffer, a local attacker can trigger an Out-of-Memory (OOM) condition. While an exploit has been published, the project has not yet released a formal patch at the time of reporting. The attack requires local access and low privileges.

Affected products

  • HdrHistogram HdrHistogram Up to 2.2.2

Timeline

  • 2026-07-05: advisory: NVD publication date
  • 2026-07-05: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats