An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted tensor payload.
To remediate this issue, users should upgrade to version 0.37.0 or above.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 17:17
Updated : 2026-09-10 19:54
NVD link : CVE-2026-85228
Mitre link : CVE-2026-85228
CVE.ORG link : CVE-2026-85228
JSON object : View
Products Affected
No product.
CWE
CWE-190
Integer Overflow or Wraparound
