PT-2026-90720 · Maven · Zstd-Jni
CVE-2026-90560
·
Published
2026-09-12
·
Updated
2026-09-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
zstd-jni versions 1.2.0 through 1.5.7-13
Description
An out-of-bounds read exists in the
ZstdDictDecompress constructor. This occurs because the offset and length arguments are not validated against the dictionary array bounds, allowing an attacker to provide arbitrary values to read memory beyond the end of the supplied array, which may lead to JVM termination.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zstd-Jni