{"id":"CVE-2026-102554","title":"Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError","summary":"Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing Compac…","severity":"none","cwe":["CWE-502","CWE-770"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T18:17:01.380","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102554","references":[{"url":"https://github.com/google/guava/commit/b931fe9d6d5cf00bc55714ad3308d086f71850fe","label":"cve-coordination@google.com"},{"url":"https://github.com/google/guava/releases/tag/v33.7.2","label":"cve-coordination@google.com"},{"url":"https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94","label":"cve-coordination@google.com"},{"url":"https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"ingestedAt":"2026-10-09T17:04:42.805Z","slug":"CVE-2026-102554","body":"## Overview\n\nAllocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}