CVE-2026-93452
snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination.
- Published Sep 18, 2026
- CVSS 8.7 high
- 0.7% chance of exploitation in the next 30 days (EPSS)