CVE-2026-102554
Denial of Service via Eager Array Allocation During Deserialization in Guava
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.
| CWE | CWE-770 CWE-502 |
| Vendor | |
| Product | guava |
| Ecosystems | |
| Industries | Technology |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for google guava
Be the first to know when new unknown vulnerabilities affecting google guava are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google / Guava
4.0 < 33.7.2
References
Credits
Kaya Emre Arikan (https://github.com/kemrec)