{"id":"CVE-2026-108104","summary":"Xerial snappy-java 1.1.7.4 before 1.1.10.10 Double Release of Pooled Buffers in SnappyFramedInputStream","details":"Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.","aliases":["GHSA-c73m-r934-8qvg"],"modified":"2026-10-11T07:04:30.926596335Z","published":"2026-10-09T14:33:28.705Z","database_specific":{"cwe_ids":["CWE-415"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108104.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108104.json"},{"type":"ADVISORY","url":"https://github.com/xerial/snappy-java/releases/tag/v1.1.10.10"},{"type":"ADVISORY","url":"https://github.com/xerial/snappy-java/security/advisories/GHSA-c73m-r934-8qvg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-108104"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/xerial-snappy-java-1.1.7.4-before-1.1.10.10-double-release-of-pooled-buffers-in-snappyframedinputstream"},{"type":"FIX","url":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea"},{"type":"PACKAGE","url":"https://github.com/xerial/snappy-java"},{"type":"ARTICLE","url":"https://github.com/xerial/snappy-java/blob/v1.1.10.9/src/main/java/org/xerial/snappy/SnappyFramedInputStream.java#L243"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xerial/snappy-java","events":[{"introduced":"38b5af815fc01b9ae0aaec6d4deb7c735599eec0"},{"fixed":"e993fe1c8e790526054566cd8f4f01ed9af4cad0"},{"fixed":"139a53090a6662298924fd75d21f4769b4a219ea"}],"database_specific":{"extracted_events":[{"introduced":"1.1.7.4"},{"fixed":"1.1.10.10"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v1.1.10.9","v1.1.10.8","v1.1.10.7","v1.1.10.6","v1.1.10.5","v1.1.10.4","v1.1.10.3","v1.1.10.2","v1.1.10.1","v1.1.10.0","v1.1.9.1","v1.1.9.0","1.1.8.4","1.1.8.3","1.1.8.2","1.1.8.1","1.1.8","1.1.7.8","1.1.7.7","1.1.7.6","1.1.7.5","1.1.7.4"],"database_specific":{"vanir_signatures_modified":"2026-10-11T07:04:30Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108104.json","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"function":"readFile","file":"src/test/java/org/xerial/snappy/CalgaryTest.java"},"deprecated":false,"digest":{"function_hash":"155022529002649781835160658768467074022","length":325},"id":"CVE-2026-108104-0059a3ea","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyOutputStreamTest.java"},"deprecated":false,"digest":{"line_hashes":["316272239694373271635582640717954677692","235029187641440880220037530125180988924","310166364782598188496188964810354022344","126641534053575607446637691305012453878","241403037786949335450112946168208947258","145137144516687440239391931272620034594","5477489812550336068412064162040902020","135830016603152746245380887452439981897","133155379773904697441863632859872565750","153814892967420787470631623851040067010","37923874256497139524781187146282324630","205255942475901411793308506353645575369","254253057019803095989254330390974244613","4844638938976480762792408771873573993","209902762811374571327355713421672952109","20355640967657943890713516920886618392"],"threshold":0.9},"id":"CVE-2026-108104-1fa121b0","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyTest.java","function":"simpleUsage"},"deprecated":false,"digest":{"length":367,"function_hash":"318331255988126760802859001064340205526"},"id":"CVE-2026-108104-2b345cf9","signature_type":"Function"},{"id":"CVE-2026-108104-3903821b","signature_type":"Line","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/test/java/org/xerial/snappy/SnappyBoundsCheckTest.java"},"deprecated":false,"digest":{"line_hashes":["157472517048614072669487047216922942986","247651575828427992869952421737658027110"],"threshold":0.9}},{"source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"function":"autoLoad","file":"src/test/java/org/xerial/snappy/SnappyLoaderTest.java"},"deprecated":false,"digest":{"function_hash":"258755003522646275601672107016795098147","length":91},"id":"CVE-2026-108104-3949e4c3","signature_type":"Function","signature_version":"v1"},{"target":{"file":"src/test/java/org/xerial/snappy/SnappyInputStreamTest.java","function":"readResourceFile"},"deprecated":false,"digest":{"function_hash":"106593095799754506929447380629364570237","length":191},"id":"CVE-2026-108104-42f72366","signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0"},{"target":{"function":"isValidCompressedData","file":"src/test/java/org/xerial/snappy/SnappyTest.java"},"deprecated":false,"digest":{"function_hash":"182300834303361720698388721643217283727","length":366},"id":"CVE-2026-108104-57cac254","signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0"},{"source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyLoaderTest.java","function":"main"},"deprecated":false,"digest":{"function_hash":"127498238867205854996727122452809558491","length":159},"id":"CVE-2026-108104-6ebb637f","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyLoaderTest.java"},"deprecated":false,"digest":{"line_hashes":["39911617872340573648409509013167071713","271904307541386554181946576144617774203","52155207813030187534326746876086962760","88785435040048543501203704638868321890","171048297520192394420426521088591013234","180360143891012157245691768498992156096","42941700509837337217265372272812811783","324892616569726560879096382398508170112","333410025264323505849953367466459658243","192191656012822872469220426890881504868","313061490427315532261413690397110548223","97847209332425690497652675413581409484","211819293187858888607301585129365275903","288324550680566739374676905258376856961","103355551001331205722471626472194113145","109332196671835637010783205579194848153","5836841605509240504725819837729876454","172433770889767115880249869934045844816","35788849923952351685994173877866088650","55371172355943830138528732379709521937","98064791950020430931416125298422010821","267640334322887306781112318285042789003","71416475361938756826333255126293739065","206666886201052569974037019161841744886","109155083865186348058517127938964884540","206244195821604994476298921247412628252","160663013135210889435102573033435373658"],"threshold":0.9},"id":"CVE-2026-108104-7035250d","signature_type":"Line"},{"id":"CVE-2026-108104-70d0e7ae","signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"function":"openByteStream","file":"src/test/java/org/xerial/snappy/SnappyLoaderTest.java"},"deprecated":false,"digest":{"function_hash":"140160685570787230902764161206459251764","length":211}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/CalgaryTest.java"},"deprecated":false,"digest":{"line_hashes":["68684560039007273339798285139894925558","120682730003311125173307409892846375995","205578296217439807852027037648985182815","253406032764328764320434017994316351157","206944729579204793356481041142303038552","247981788312827076440982373569105264200","73130714982039708057151172911869590873","192676092549421238464527566228340798046","100701100070142870043985891703832873027","290354643803540680111591235985040945166","214556733757965091745426420810219663399","113712375471884196817362642632522908471"],"threshold":0.9},"id":"CVE-2026-108104-7f4a1ea9"},{"digest":{"line_hashes":["155850079056241379656295209114566750325","198737289995645117809889847245708297270","286123580041034006069571757985564003735","238190652179993881561635884255134129969","25477390825958973486052726864051370676","89687023065414473043788152864420506168","273945159128259949477877061055279554978","33036954137238378756890258646184184801","172911949356028452712625498517726527236","278894098941060499461607302368002827379","145823720908735826317940267834775139302","190883733118240706497442282476649534223","108885841248856991386789777712395398531","257230491368587415273671113221724418464","35266390651569329974247951865727747223","331085247174595288095250406203988813287","331864281023864822894263521319585459599","86814909985443223011769005690429140115","133279306399832523913046023137375315567","3070133221377047558836873924603695773","126651765728678658429168506923949630306","134595809847664822482254743666815676464","3472682993634619537604680000163540127","147193265886490601487236823701322161039","281185601303713573751267956331309467469","123101178547833785889787769806716478723","110694122174495847682487204595549176705","209378172529807401014137670033614511824","111846052450074792690205110610891560013","212965190796779731794857742298998451164","146795597576102932397852083067233678963","69330117743938072918738395881505248221","233040514033221837757091267922872525533"],"threshold":0.9},"id":"CVE-2026-108104-8141ef33","signature_type":"Line","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/main/java/org/xerial/snappy/SnappyInputStream.java"},"deprecated":false},{"source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/main/java/org/xerial/snappy/SnappyFramedInputStream.java"},"deprecated":false,"digest":{"line_hashes":["29058858471971681441310826711046808715","165856121080703964417980785441266898930","214523029034019911838223223100027533138","301711945540994714344495504220842475738","119565343450058745618712031700243547173","71109271684760058571627280670893379486","100704011250076178077820437110162541306","137434533216293739767343576044003055133","171595779758918641575366469194745920618","158903561511711044221447282698171669954","250146807182022458093369917894458856146","232479792068409647063073176356633675819","311192032587429711184649637434513636337","128811560592276854820271015411325425957","51306000624952063049382729713689503559","286416722965658620795960047096783079412"],"threshold":0.9},"id":"CVE-2026-108104-9c0d219e","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyTest.java"},"deprecated":false,"digest":{"line_hashes":["257194718538685719751081037370977077566","268892594402638991271373231736395237693","171154123769795136105457321358714543847","330807738411479205429218428247478701080","210857450582371581431102064362022218820","324363329914351878129571517340869014929","122628240847633673540491391633503438972","35269990958640132585876188805061791785","280976351099690746789881531843928817762","118836996174502428939631865517247779698","32505892700836464161236581962057517071","128003119104291133515422626743357972865","257162984838559198392835788348146199775","206304454015352003969446976520849032685","113381888807755743201420670734799395247","321106605191114909192691502592717363243","61949275533770900772576131222468276101","29124810351751517033822692313466707496","76078738245626395513751749482605794587","11742718723122306676574553217262713682","8221042525536689695158685064047875888","141519246007607116607821869936875513227","172573516532868898452406951484811325732","261784772187059731958250416371134516552","272700081849186632417752876898593559774","32266178738651309818569696661181899420","64066167361540636588217983323708610039","149370110721990796948685063648074261744","73103666551624653988298515034426623674","147975884709584853577104828234601692158","158030343053328675314174556125822281202","114946336029421416987084557249517360545","51591780828232856792261810978503226885","173903671349518722274747034955105348419","23680920332368764092048061322250142397","98548203155693364455117381060219553461","157670482671788058959041959431919702266","256070159223810470248444219763910262624"],"threshold":0.9},"id":"CVE-2026-108104-a631698c","signature_type":"Line"},{"source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyLoaderTest.java","function":"load"},"deprecated":false,"digest":{"function_hash":"336045345452184491486280475129978255787","length":121},"id":"CVE-2026-108104-b6ba540f","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"214510138248501046918249000963826033173","length":1751},"id":"CVE-2026-108104-cee502c8","signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/main/java/org/xerial/snappy/SnappyInputStream.java","function":"hasNextChunk"}},{"signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/main/java/org/xerial/snappy/SnappyFramedInputStream.java","function":"allocateBuffersBasedOnSize"},"deprecated":false,"digest":{"function_hash":"29321272755463883629295747447826901722","length":438},"id":"CVE-2026-108104-d01d5f3f","signature_type":"Function"},{"id":"CVE-2026-108104-e6e7c125","signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyOutputStreamTest.java","function":"test"},"deprecated":false,"digest":{"function_hash":"198753998911239562008411737821469732893","length":1061}},{"digest":{"threshold":0.9,"line_hashes":["327883481541750417674647099004710607757","199620089605551700451705958204903296962","191847292982665403282517308561779507198","96075109046600278670516200401571550888","238199910848654419378949573257912289631","8290030381069321613249892039105949905","267473026126321767848156844296736182813","293585635032282484048770927614987745404","244568578810546714101374451203072944299","55539875696424436593817319816491914678","178143802265235016865686288272463878841","214641678685883510194653178387343639765","41664277966024799770757866147188200426","53921980567137814717929115959184924968","320273014846546063082889287146778339131","8969999436303936526974794075480597674"]},"id":"CVE-2026-108104-eec1c7a9","signature_type":"Line","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/e993fe1c8e790526054566cd8f4f01ed9af4cad0","target":{"file":"src/test/java/org/xerial/snappy/SnappyInputStreamTest.java"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","target":{"file":"src/main/java/org/xerial/snappy/SnappyFramedInputStream.java","function":"ensureBuffer"},"deprecated":false,"digest":{"function_hash":"251474504383367227080904826590860294955","length":1665},"id":"CVE-2026-108104-f76c83ef"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}