Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-102554

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 09, 2026
Vendor unknown

Description

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

References