Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory. | |
| Title | snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods | |
| First Time appeared |
Xerial
Xerial snappy-java |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xerial
Xerial snappy-java |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T20:52:30.715Z
Reserved: 2026-09-17T22:45:30.561Z
Link: CVE-2026-93451
Updated: 2026-09-21T16:28:45.579Z
Status : Received
Published: 2026-09-18T00:17:49.380
Modified: 2026-09-21T21:17:17.990
Link: CVE-2026-93451
No data.
OpenCVE Enrichment
Updated: 2026-09-19T08:00:13Z