CVE-2026-90559 – snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress

​CVE ID :CVE-2026-90559

Published : Sept. 12, 2026, 6:16 p.m. | 1 hour, 34 minutes ago

Description :snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More