VulnSea

xerial has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.5 (high). The most common weakness class is CWE-787 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
3 prev 0

Weakness classes

Products

  • snappy-java 3
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

xerial vulnerabilities

CVEs affecting xerial, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-93451Medium· 6.5
5d ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Atta…

Sunlitxerial · snappy-javaEPSS 0.30%via NVD
CVE-2026-93452High· 7.5PoC
5d ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination bu…

Midnightxerial · snappy-javaEPSS 0.49%via NVD
CVE-2026-90559High· 7.5
1w ago

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compress…

Twilightxerial · snappy-javaEPSS 0.35%via NVD
xerial vulnerabilities (CVEs) · VulnSea