CVE-2026-14686

Source
https://cve.org/CVERecord?id=CVE-2026-14686
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14686.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14686
Downstream
Published
2026-07-05T00:00:10.233Z
Modified
2026-07-18T03:41:39.453983552Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
HdrHistogram Range Check DoubleHistogram.java org.HdrHistogram.DoubleHistogram.recordValue comparison
Details

A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

Database specific
{
    "cwe_ids": [
        "CWE-697"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14686.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.2.0"
                },
                {
                    "last_affected": "2.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "isDisputed": true
}
References

Affected packages

Git / github.com/hdrhistogram/hdrhistogram

Affected ranges

Type
GIT
Repo
https://github.com/hdrhistogram/hdrhistogram
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.2.1"
        },
        {
            "last_affected": "2.2.1"
        },
        {
            "introduced": "2.2.2"
        },
        {
            "last_affected": "2.2.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.2.1
2.2.2
HdrHistogram-2.*
HdrHistogram-2.2.1
HdrHistogram-2.2.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14686.json"