CVE-2026-89046

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 18:18

Updated : 2026-09-10 19:54


NVD link : CVE-2026-89046

Mitre link : CVE-2026-89046

CVE.ORG link : CVE-2026-89046


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read