๐Ÿ” CVE Alert

CVE-2026-102554

UNKNOWN 0.0

Denial of Service via Eager Array Allocation During Deserialization in Guava

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

CWE CWE-770 CWE-502
Vendor google
Product guava
Ecosystems
Industries
Technology
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for google guava

Be the first to know when new unknown vulnerabilities affecting google guava are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Google / Guava
4.0 < 33.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94 github.com: https://github.com/google/guava/commit/b931fe9d6d5cf00bc55714ad3308d086f71850fe github.com: https://github.com/google/guava/releases/tag/v33.7.2

Credits

Kaya Emre Arikan (https://github.com/kemrec)