Denial of Service Vulnerability in Google Guava Library
CVE-2026-102554
8.2HIGH
What is CVE-2026-102554?
A flaw in the Google Guava library allows attackers to exploit the deserialization of Java objects, specifically within CompactHashMap, CompactHashSet, or MapMakerInternalMap instances. The library allocates resources without proper limits or throttling during deserialization operations, potentially leading to memory exhaustion. Attackers can craft specific serialization streams that, when processed, cause the application to run out of memory, resulting in a Denial of Service. Users of Google Guava versions 4.0 through 33.7.1 are advised to update to version 33.7.2 or later to mitigate this issue.
Affected Version(s)
Guava 4.0 < 33.7.2
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kaya Emre Arikan (https://github.com/kemrec)