CVE-2026-102554EPSS p26.8%
CVE-2026-102554CVE-2026-102554
Description
Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.
Scoring
| EPSS | 0.35% probability of exploitation · percentile 26.8% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |