CVE-2026-14685: HdrHistogram AbstractHistogram AbstractHistogram.java recordValueWithCount state issue
A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14685?
The severity of CVE-2026-14685 is rated as low with a score of 3.3.
What component is affected by CVE-2026-14685?
CVE-2026-14685 affects the AbstractHistogram component of HdrHistogram.
How can I mitigate CVE-2026-14685?
Mitigation for CVE-2026-14685 involves upgrading to a patched version of HdrHistogram beyond 2.2.2.
What is the impact of exploiting CVE-2026-14685?
Exploitation of CVE-2026-14685 can lead to a state issue resulting from manipulation of the argument Count.
Is there a workaround for CVE-2026-14685?
Currently, the recommended workaround for CVE-2026-14685 is to avoid using the vulnerable function recordValueWithCount until a fix is applied.