Vulnerability Description
snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/xerial/snappy-java
- https://github.com/xerial/snappy-java/blob/v1.1.10.8/src/main/java/org/xerial/sn
- https://github.com/xerial/snappy-java/issues/728
- https://www.vulncheck.com/advisories/snappy-java-through-1.1.10.8-out-of-bounds-
FAQ
What is CVE-2026-90559?
CVE-2026-90559 is a vulnerability with a CVSS score of 7.5 (HIGH). snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size...
How severe is CVE-2026-90559?
CVE-2026-90559 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90559?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.