Skip to content

[GHSA-mrhq-xxpp-qf7j] Add affected package and fixed version for snappy-java - #10135

Open
xerial wants to merge 1 commit into
github:xerial/advisory-improvement-10135from
xerial:xerial/GHSA-mrhq-xxpp-qf7j
Open

xerial wants to merge 1 commit into
github:xerial/advisory-improvement-10135from
xerial:xerial/GHSA-mrhq-xxpp-qf7j

Conversation

@xerial

@xerial xerial commented Oct 3, 2026

Copy link
Copy Markdown

I'm the maintainer of snappy-java (xerial/snappy-java).

This advisory (CVE-2026-90559) currently has an empty affected list, so dependency scanners flag every snappy-java version and report no fix. This PR adds:

The fix: Snappy.uncompress(ByteBuffer, ByteBuffer) now throws IllegalArgumentException when uncompressed.remaining() is smaller than the uncompressed length declared in the compressed data. 1.1.10.9 is published on Maven Central.

Fix commit: xerial/snappy-java@943c604

Copilot AI balanced review requested due to automatic review settings October 3, 2026 17:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The package coordinates, version range, fix commit, and release are consistent with the upstream sources.

Review effort: Balanced
Findings: None

What changed in this PR

Adds accurate Maven affected-version metadata and remediation references for CVE-2026-90559.

Changes:

  • Marks versions through 1.1.10.8 as affected and 1.1.10.9 as fixed.
  • Adds advisory, fix, release, and package references.
File Description
GHSA-mrhq-xxpp-qf7j.json Updates affected ranges and supporting references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions
github-actions Bot changed the base branch from main to xerial/advisory-improvement-10135 October 3, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants