Xerial maintains the Snappy-Java compression library, a narrowly scoped but widely embedded component used across data processing and storage systems for lossless compression. The observed vulnerability signal centers on resource-management and integer-handling weaknesses—unthrottled allocation and integer overflow—that arise in parsing and decompression logic and can propagate through any downstream application that bundles the library.
The number and severity of CVEs published that impact products developed by Xerial over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43642HIGH snappy-java is a Java port of the snappy, a fast C++ compresser/decompresser developed by Google. The SnappyInputStream was found to be vulnerable to Denial of Service (DoS) attack | Sep 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-34454HIGH snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur in versions prior to 1.1.10.1, causing an unrecoverable fata | Jun 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-34455HIGH snappy-java is a fast compressor/decompressor for Java. Due to use of an unchecked chunk length, an unrecoverable fatal error can occur in versions prior to 1.1.10.1.
The code in | Jun 15, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-34453HIGH snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur in versions prior to 1.1.10.1, causing a fatal error.
The f | Jun 15, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xerial.
Media articles that mention a CVE ID that affects a product developed by Xerial — matched by CVE ID, not by vendor name.