Remediation:
Upgrade to com.google.guava:guava@33.7.2-jre.
Overview
com.google.guava:guava is a set of core libraries that includes new collection types (such as multimap and multiset,immutable collections, a graph library, functional types, an in-memory cache and more.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the readObject deserialization paths in CompactHashMap, CompactHashSet, and MapMakerInternalMap. An attacker can crash a Java process with an OutOfMemoryError by supplying a crafted serialized stream that declares an oversized element count or initial capacity. During deserialization, CompactHashMap and CompactHashSet use the attacker-controlled size to initialize their backing storage, and MapMakerInternalMap propagates the attacker-controlled size into segment table allocation, letting a tiny payload force a much larger heap allocation.
Remediation
Upgrade com.google.guava:guava to version 33.7.2-jre or higher.