Denial of Service Vulnerability in Google Guava Library
CVE-2026-102554

8.2HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-102554?

A flaw in the Google Guava library allows attackers to exploit the deserialization of Java objects, specifically within CompactHashMap, CompactHashSet, or MapMakerInternalMap instances. The library allocates resources without proper limits or throttling during deserialization operations, potentially leading to memory exhaustion. Attackers can craft specific serialization streams that, when processed, cause the application to run out of memory, resulting in a Denial of Service. Users of Google Guava versions 4.0 through 33.7.1 are advised to update to version 33.7.2 or later to mitigate this issue.

Affected Version(s)

Guava 4.0 < 33.7.2

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kaya Emre Arikan (https://github.com/kemrec)
.