Double Release Vulnerability in Xerial Snappy-Java Library
CVE-2026-108104

6.3MEDIUM

Key Information:

Vendor

Xerial

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108104?

The vulnerability in Xerial's snappy-java library arises from a flaw in the SnappyFramedInputStream component, where improper handling of pooled buffers can result in a double release condition. This can occur when an attacker crafts framed data with an excessively large declared chunk length, leading to an OutOfMemoryError. As a consequence, shared backing arrays may inadvertently expose or overwrite decompressed data from other streams, presenting significant data security risks.

Affected Version(s)

snappy-java 1.1.7.4 < 1.1.10.10

snappy-java 1.1.10.10

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Bao, PayPal Cyber Security Team
.