---
id: CVE-2026-102554
title: >-
  Allocation of resources without limits or throttling (CWE-770) during Java
  object deserialization in Google Guava versions 4.0 through 33.7.1 allows an
  attacker to cause a Denial of Service via OutOfMemoryError
summary: >-
  Allocation of resources without limits or throttling (CWE-770) during Java
  object deserialization in Google Guava versions 4.0 through 33.7.1 allows an
  attacker to cause a Denial of Service via OutOfMemoryError. When deserializing
  Compac…
severity: none
cwe:
  - CWE-502
  - CWE-770
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T18:17:01.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102554'
references:
  - url: >-
      https://github.com/google/guava/commit/b931fe9d6d5cf00bc55714ad3308d086f71850fe
    label: cve-coordination@google.com
  - url: 'https://github.com/google/guava/releases/tag/v33.7.2'
    label: cve-coordination@google.com
  - url: 'https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94'
    label: cve-coordination@google.com
  - url: 'https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
ingestedAt: '2026-10-09T17:04:42.805Z'
---

## Overview

Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
