CVE-2026-102554

NameCVE-2026-102554
DescriptionAllocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1150495

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
guava-libraries (PTS)bookworm31.1-1vulnerable
trixie32.0.1-1vulnerable
forky, sid33.7.1-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
guava-librariessource(unstable)(unfixed)1150495

Notes

https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94
Fixed by: https://github.com/google/guava/commit/b931fe9d6d5cf00bc55714ad3308d086f71850fe (master)
Fixed by: https://github.com/google/guava/commit/a0d0c36432c4cc7aa4b5063bab9f20d3d18fe9fc (v33.7.2)

Search for package or bug name: Reporting problems