CVE-2026-14684: HdrHistogram AbstractHistogram.java memory allocation
A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14684?
The severity of CVE-2026-14684 is classified as low with a score of 3.3.
How do I fix CVE-2026-14684?
To fix CVE-2026-14684, upgrade HdrHistogram to version 2.2.3 or later.
What software is affected by CVE-2026-14684?
CVE-2026-14684 affects HdrHistogram versions up to 2.2.2.
What type of vulnerability is CVE-2026-14684?
CVE-2026-14684 is a memory allocation flaw that occurs in the decoding function of the HdrHistogram library.
What are the potential consequences of CVE-2026-14684?
The potential consequences of CVE-2026-14684 include uncontrolled memory allocation, which may lead to Denial of Service.