You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
CVE-2026-90559 is reported against latest version 1.1.10.8 #738
Hi, I'm checking the status of CVE-2026-90559 affecting snappy-java version 1.1.10.8. We are using this library as a dependency in a product and have been flagged by our security scanner.
Is a fix planned? If so, could you share the expected fixed version and an approximate release date? Is there a recommended workaround in the meantime?
CVE-2026-90559 (#728) is fixed in #739, now merged to main: Snappy.uncompress(ByteBuffer, ByteBuffer) checks the destination capacity before calling native code. The fix will ship in 1.1.10.9. Until then, check uncompressed.remaining() >= Snappy.uncompressedLength(compressed) before calling it.
Are there any plans in fixing reported vulnerability cve-2026-90559:
https://nvd.nist.gov/vuln/detail/cve-2026-90559