SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM
Published Aug 4, 2026
7.1
HIGHCVSS 4.0
EPSS 0.55%
Description
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload declaring an arbitrarily large decompressed size in a retry task argument, causing the JVM to attempt an unbounded array allocation and triggering an unrecoverable java.lang.OutOfMemoryError when the task is dispatched through the retry-task pipeline.
Affected products
-
- Version 1.7.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Aizuda | SnailJob (snail-job) | affected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52851 Advisory
- https://gitee.com/aizuda/snail-job product
- https://gitee.com/aizuda/snail-job/issues/ICRJMI issue-tracking
- https://gitee.com/aizuda/snail-job/releases#release-vsj2.0.0 patch
- https://www.vulncheck.com/advisories/snailjob-denial-of-service-via-furyutil-deserialize-oom third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52851 | Advisory | |
| https://gitee.com/aizuda/snail-job | product | |
| https://gitee.com/aizuda/snail-job/issues/ICRJMI | issue-tracking | |
| https://gitee.com/aizuda/snail-job/releases#release-vsj2.0.0 | patch | |
| https://www.vulncheck.com/advisories/snailjob-denial-of-service-via-furyutil-deserialize-oom | third-party-advisory |
Change history (0)
No recorded changes yet.