PT-2026-89055 · Git+2 · Zstd-Jni

CVE-2026-87825

·

Published

2026-08-16

·

Updated

2026-09-09

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14469
CVE-2026-87825
GHSA-947W-PXJJ-C7M9

Affected Products

Zstd-Jni