Snappier
A near-C++ performance implementation of the Snappy compression algorithm for .NET. Snappier is ported to C# directly from the official C++ implementation, with the addition of support for the framed stream format. By avoiding P/Invoke, Snappier is fully cross-platform and works on both Linux and Windows and against any CPU supported by .NET. However, Snappier performs best in .NET 6 and later on little-endian x86/64 processors with the help of System.Runtime.Instrinsics.
Activity
- Latest release
- 4mo ago
- Total releases
- 16
- Cadence
- ~42 days
- Last 12 months
- 4
Details
- License
- BSD-3-Clause
- First release
- Oct 22, 2020
| Version | Released | |
|---|---|---|
1.3.1
patch
|
1.3.1
patch
Dependencies (2)
|
|
1.3.0
minor
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.3.0
minor
Dependencies (2)
|
|
1.3.0-beta.2
pre
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.3.0-beta.2
pre
Dependencies (2)
|
|
1.3.0-beta.1
pre
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.3.0-beta.1
pre
Dependencies (3)
|
|
1.2.0
minor
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.2.0
minor
Dependencies (3)
|
|
1.2.0-beta0001
pre
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.2.0-beta0001
pre
Dependencies (3)
|
|
1.1.6
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.6
patch
Dependencies (3)
|
|
1.1.5
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.5
patch
Dependencies (3)
|
|
1.1.4
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.4
patch
Dependencies (3)
|
|
1.1.3
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.3
patch
Dependencies (3)
|
|
1.1.2
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.2
patch
Dependencies (3)
|
|
1.1.1
patch
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.1.1
patch
Dependencies (3)
|
|
1.1.0
minor
2 CVEs
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev
CVE-2023-28638
GHSA-838x-pcvx-6p5w
Mar 27, 2023
Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer
7.0
/ 10
High
Network
High
None
None
Unchanged
Low
Low
High
ImpactThis is a buffer overrun vulnerability that can affect any user of Snappier 1.1.0. In this release, much of the code was rewritten to use byte references rather than pointers to pinned buffers. This change generally improves performance and reduces workload on the garbage collector. However, when the garbage collector performs compaction and rearranges memory, it must update any byte references on the stack to refer to the updated location. The .NET garbage collector can only update these byte references if they still point within the buffer or to a point one byte past the end of the buffer. If they point outside this area, the buffer itself may be moved while the byte reference stays the same. There are several places in 1.1.0 where byte references very briefly point outside the valid areas of buffers. These are at locations in the code being used for buffer range checks. While the invalid references are never dereferenced directly, if a GC compaction were to occur during the brief window when they are on the stack then it could invalidate the buffer range check and allow other operations to overrun the buffer. This should be very difficult for an attacker to trigger intentionally. It would require a repetitive bulk attack with the hope that a GC compaction would occur at precisely the right moment during one of the requests. However, one of the range checks with this problem is a check based on input data in the decompression buffer, meaning malformed input data could be used to increase the chance of success. Note that any resulting buffer overrun is likely to cause access to protected memory, which will then cause an exception and the process to be terminated. Therefore, the most likely result of an attack is a denial of service. PatchesThis is patched in release 1.1.1. WorkaroundsPinning any buffers to a fixed location before using them for compression or decompression should mitigate some, but not all, of these cases. At least one temporary decompression buffer is internal to the library and never pinned. Affected versions
1.1.0
Fixed in
1.1.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
1.1.0
minor
Dependencies (3)
|
|
1.0.0
initial
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.0.0
initial
Dependencies (3)
|
|
1.0.0-beta002
pre
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.0.0-beta002
pre
Dependencies (3)
|
|
1.0.0-beta001
pre
1 CVE
CVE-2026-44302
GHSA-pggp-6c3x-2xmx
May 06, 2026
Snappier has an infinite loop during SnappyStream decompression with malformed framed input
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
Summary
DetailsThe hang manifests as a userspace busy loop with SnappyStreamDecompressor.Decompress repeatedly calling Crc32CAlgorithm.Append. The exact non-terminating loop in or above Decompress has not been traced further. PoC
ImpactA caller using Affected versions
1.0.0
1.0.0-beta001
1.0.0-beta002
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0
1.2.0-beta0001
+ 1 more Show less
1.3.0
Fixed in
1.3.1
References Updated May 13, 2026 · Source: OSV.dev |
1.0.0-beta001
pre
Dependencies (3)
|