CVE-2026-90560

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-12 18:16

Updated : 2026-09-14 16:17


NVD link : CVE-2026-90560

Mitre link : CVE-2026-90560

CVE.ORG link : CVE-2026-90560


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read