CVE-2026-102554: Denial of Service via Eager Array Allocation During Deserialization in Guava

Published Oct 9, 2026
·
Updated

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

Affected Software

1 affected component
Google Guava>=4.0<=33.7.1

Event History

Oct 9, 2026
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionWeakness

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications are exposed if they use Google Guava versions 4.0 through 33.7.1 and deserialize attacker-controlled or otherwise untrusted Java serialization streams containing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances.

2

What does an attacker need to trigger the denial of service?

An attacker needs to supply a crafted serialization stream with a caller-specified size value that causes Guava to eagerly allocate a large array during deserialization. Successful exploitation can exhaust memory and produce an OutOfMemoryError.

3

How can I determine whether my deployment is affected?

Check the Guava version in use and identify whether the application deserializes Java objects from untrusted inputs. Versions 4.0 through 33.7.1 are affected when deserializing the listed Guava collection or map types.

4

What version addresses the issue?

The affected range ends at 33.7.1, and Google Guava 33.7.2 is referenced as the release containing the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203