Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.xerial/snappy-java

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-108106 is a high-severity vulnerability in xerial snappy-java before version 1.1.10.9. It involves unbounded memory allocation triggered by attackers supplying crafted compressed input with a large uncompressed length. This can cause the Java Virtual Machine (JVM) to allocate up to 2 GB of memory, leading to OutOfMemoryError and denial of service conditions.

Join the discussion
0

A double free vulnerability exists in xerial snappy-java versions from 1.1.7.4 up to but not including 1.1.10.10. The flaw occurs in SnappyFramedInputStream when replacement allocation fails, causing pooled buffers to be released twice. This can lead to OutOfMemoryError and potentially expose or overwrite decompressed data from other streams.

Join the discussion

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.

Join the discussion

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory.

Join the discussion

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/org.xerial/snappy-java
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses