CVE-2026-14686: HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14686?
The severity of CVE-2026-14686 is rated as low with a score of 3.3.
How do I fix CVE-2026-14686?
To fix CVE-2026-14686, update to a version of HdrHistogram that is higher than 2.2.2.
What component is affected by CVE-2026-14686?
CVE-2026-14686 affects the org.HdrHistogram.DoubleHistogram function in HdrHistogram's Range Check component.
What impact does CVE-2026-14686 have?
The impact of CVE-2026-14686 is an incorrect comparison during the execution of the recordValue function.
When was CVE-2026-14686 published?
CVE-2026-14686 was published on July 5, 2026.