t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatched header fields to trigger ArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the parsing thread.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 11:17
Updated : 2026-09-10 15:53
NVD link : CVE-2026-87962
Mitre link : CVE-2026-87962
CVE.ORG link : CVE-2026-87962
JSON object : View
Products Affected
No product.
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
