| Version | Supported |
|---|---|
| 1.1.9.x | ✅ |
| < 1.1.8.x | ❌ |
Security: xerial/snappy-java
Security
SECURITY.md
-
Uncontrolled recursion and eager chunk allocation in SnappyInputStreamGHSA-6gp7-6wmv-gxqw published
Oct 3, 2026 by xerialHigh -
Double release of pooled buffers in SnappyFramedInputStream can share a buffer across streamsGHSA-c73m-r934-8qvg published
Oct 3, 2026 by xerialHigh -
Heap buffer overflow in Snappy.uncompress*Array typed-array methodsGHSA-gwq9-9ffj-mvrv published
Oct 3, 2026 by xerialHigh -
Out-of-bounds write in Snappy.uncompress(ByteBuffer, ByteBuffer)GHSA-wmgv-28fv-894x published
Oct 3, 2026 by xerialHigh -
JVM crash from unchecked ranges in Snappy.arrayCopy and SnappyOutputStream.rawWriteGHSA-xqrx-qh46-34m7 published
Oct 3, 2026 by xerialModerate -
Out-of-bounds read and write in Snappy.compress and rawCompress from unchecked offsets and output sizeGHSA-38f5-hf66-x965 published
Oct 3, 2026 by xerialModerate -
Unbounded memory allocation from attacker-declared uncompressed length in snappy-javaGHSA-q233-g92q-qxp6 published
Oct 3, 2026 by xerialHigh -
Missing upper bound check on chunk length in snappy-java can lead to Denial of Service (DoS) impactGHSA-55g7-9cwv-5qfv published
Sep 23, 2023 by xerialHigh -
Integer overflow in shuffle leads to DoSGHSA-pqr6-cmr2-h8hf published
Jun 14, 2023 by xerialModerate -
Integer overflow in compress leads to DoSGHSA-fjpj-2g6w-x25r published
Jun 14, 2023 by xerialModerate
Learn more about advisories related to xerial/snappy-java in the GitHub Advisory Database