Back

HIGH

SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM

Published Aug 4, 2026

Description

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload declaring an arbitrarily large decompressed size in a retry task argument, causing the JVM to attempt an unbounded array allocation and triggering an unrecoverable java.lang.OutOfMemoryError when the task is dispatched through the retry-task pipeline.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 4, 2026
Updated Sep 24, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Received
Modified Aug 5, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Aug 4, 2026
Updated Sep 24, 2026
Exploited since n/a
EUVD-2026-52851