Junglewise Threat Intelligence

CVE-2026-90559: snappy-java out-of-bounds write in uncompress

CVE-2026-90559 · Severity: high · CVSS 7.5 · Published 2026-09-12

Technologies: Xerial Snappy-Java. Vendors: Xerial.

Executive brief

snappy-java is a Java library that compresses and decompresses data using the Snappy algorithm, commonly used in data processing and storage systems. A flaw in the decompression function fails to validate the destination buffer size, allowing attackers to supply compressed data that expands larger than expected, causing the library to write past buffer boundaries and crash the Java application.

Technical details

The vulnerability is an out-of-bounds write in the Snappy.uncompress(ByteBuffer, ByteBuffer) method, which does not validate the destination buffer capacity against the decompressed output size. An attacker can craft valid compressed data that decompresses to a size larger than the destination buffer, causing memory writes past buffer boundaries. This occurs when decompressing attacker-controlled compressed payloads, without requiring authentication or prior access. Exploitation results in JVM termination and potential denial of service; code execution impact is not confirmed. Patches are expected in versions after 1.1.10.8.

Affected products

  • Xerial snappy-java through 1.1.10.8

Timeline

  • 2026-09-12: disclosed

References

Related threats