CVE-2026-87877

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 15:17

Updated : 2026-09-09 20:16


NVD link : CVE-2026-87877

Mitre link : CVE-2026-87877

CVE.ORG link : CVE-2026-87877


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free