zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 10:22
Updated : 2026-09-14 13:19
NVD link : CVE-2026-87795
Mitre link : CVE-2026-87795
CVE.ORG link : CVE-2026-87795
JSON object : View
Products Affected
No product.
CWE
CWE-125
Out-of-bounds Read
