CVE-2026-102554: Denial of Service via Eager Array Allocation During Deserialization in Guava
Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.
Affected Software
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications are exposed if they use Google Guava versions 4.0 through 33.7.1 and deserialize attacker-controlled or otherwise untrusted Java serialization streams containing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances.
What does an attacker need to trigger the denial of service?
An attacker needs to supply a crafted serialization stream with a caller-specified size value that causes Guava to eagerly allocate a large array during deserialization. Successful exploitation can exhaust memory and produce an OutOfMemoryError.
How can I determine whether my deployment is affected?
Check the Guava version in use and identify whether the application deserializes Java objects from untrusted inputs. Versions 4.0 through 33.7.1 are affected when deserializing the listed Guava collection or map types.
What version addresses the issue?
The affected range ends at 33.7.1, and Google Guava 33.7.2 is referenced as the release containing the fix.