PT-2026-89056 · Git+2 · Zstd-Jni

CVE-2026-87877

·

Published

2026-08-16

·

Updated

2026-09-09

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14470
CVE-2026-87877
GHSA-2JW3-MG7F-VW4Q

Affected Products

Zstd-Jni