CVE-2026-21452: Unbounded Array Allocation From Method Parameter

An array is allocated using a size directly from a method parameter without an explicit upper bound check wrapping the allocation. If the size is controlled by an attacker during parsing or deserialization, this can lead to unbounded memory allocation, OutOfMemoryError, and Denial of Service (DoS). Validate the size against a reasonable threshold before allo

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Java
greprules fetch cve-2026-21452-unbounded-array-allocation-from-method-parameter --engine opengrep

Description

An array is allocated using a size directly from a method parameter without an explicit upper bound check wrapping the allocation. If the size is controlled by an attacker during parsing or deserialization, this can lead to unbounded memory allocation, OutOfMemoryError, and Denial of Service (DoS). Validate the size against a reasonable threshold before allo