Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-34455

24
FAUCET Score

CVE-2023-34455 is a high-severity vulnerability in xerial snappy-java versions prior to 1.1.10.1, where unchecked chunk lengths can lead to a denial-of-service. Attackers can exploit this remotely with low complexity by providing malicious input, causing either a NegativeArraySizeException or a fatal OutOfMemoryError. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.1.10.1CPE matchmatch criteria
cpe:2.3:a:xerial:snappy-java:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.76%
Probability of exploitation in next 30 days
EPSS Percentile
75.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0176 is in the 58th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.xerial.snappy:snappy-javaFixed in: 1.1.10.1
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.5.0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 2.13.9.FinalFixed in: org.xerial.snappy/snappy-java:1.1.10.5-redhat-00001
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-K 1.10.5Fixed in: snappy-java
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.18.3.2Fixed in: snappy-java
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-Springboot 3.20.2Fixed in: snappy-java
View patch
redhatpatch availablevia redhat_api
Product: RHINT Service Registry 2.5.4 GAFixed in: snappy-java
View patch
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: snappy-java
View patch
redhatno patchvia redhat_api
Product: streams for Apache KafkaFixed in: snappy-java
redhatno patchvia redhat_api
Product: Red Hat build of Debezium 1Fixed in: snappy-java
redhatno patchvia redhat_api
Product: Red Hat build of Debezium 2Fixed in: snappy-java
redhatno patchvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: snappy-java
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 2Fixed in: snappy-java
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: log4j:2/log4j
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: log4j
redhatend of lifevia redhat_api
Product: OpenShift ServerlessFixed in: snappy-java
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Application RuntimesFixed in: snappy-java
redhatend of lifevia redhat_api
Product: Red Hat Process Automation 7Fixed in: snappy-java
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: snappy-java
redhatend of lifevia redhat_api
Product: Red Hat Decision Manager 7Fixed in: snappy-java

Vendor Advisories (2)

redhatCVE-2023-34455Moderate

snappy-java: Unchecked chunk length leads to DoS

Jun 16, 2023
mavenGHSA-qcwq-55hx-v3vhhigh

snappy-java's unchecked chunk length leads to DoS

Jun 15, 2023

References

github.com / xerial/snappy-java/blob/05c39b2ca9b5b7b39611529cc302d3d796329611/src/main/java/org/xerial/snappy/SnappyInputStream.java
Issue Tracking
github.com / xerial/snappy-java/blob/master/src/main/java/org/xerial/snappy/SnappyInputStream.java
Issue Tracking
github.com / xerial/snappy-java/commit/3bf67857fcf70d9eea56eed4af7c925671e8eaea
Patch
github.com / xerial/snappy-java/security/advisories/GHSA-qcwq-55hx-v3vh
ExploitVendor Advisory
security.netapp.com / advisory/ntap-20230818-0009
Third Party Advisory