CVE-2026-87795

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 10:22

Updated : 2026-09-14 13:19


NVD link : CVE-2026-87795

Mitre link : CVE-2026-87795

CVE.ORG link : CVE-2026-87795


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read