CVE-2026-102554

HIGH CVSS 4.0: 8.2
Updated Oct 09, 2026
Google
Parameter Value
CVSS 8.2 (HIGH)
Affected Versions 4.0 — 33.7.1
Type CWE-770 (Allocation Without Limits), CWE-502 (Deserialization of Untrusted Data)
Vendor Google
Public PoC No

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0